Configure the Do Not Decrypt List for IPS
Secure Access must decrypt traffic in order to allow the Intrusion Prevention feature to inspect the traffic for threats.
However, decrypting traffic to certain sites, such as health-related or financial sites, may be restricted by privacy laws in some geographic regions.
Use the default Do Not Decrypt List to specify destinations that should not be decrypted by intrusion prevention processes (IPS.)
Web security features, for example those configured in a Security Profile, also require decryption in order to be effective; you can use this list for web security decryption, or you can create and use a different list or lists for web security.
For details, see Important Information About Do Not Decrypt Lists.