Software Secure Access
Activity Manage

Cisco Secure Access Help Manage Traffic Decryption Internet Access Features That Require Decryption

Last updated: Aug 14, 2025

Internet Access Features That Require Decryption

The following features require decryption or do not work effectively on encrypted traffic:

  • Intrusion prevention (IPS) for traffic to internet destinations.

    Traffic must be decrypted to inspect HTTPS traffic for known threats and behaviors.

  • Security features configured in security profiles.

    Decryption is required for inspection by the security and acceptable use features. The security profile specified in any internet access rule should have decryption enabled, unless the destinations are trusted.

  • Remote browser isolation (RBI).

    If you choose Isolate as the rule action in an internet access rule, affected traffic must be decrypted. Enable decryption in the security profile that you choose for that rule.

Sites that use HTTP rather than HTTPS do not require decryption to benefit from the functionality listed above. However, most sites use HTTPS. Enforcement based on threat categories never requires decryption.