Software Secure Firewall Threat Defense
Platform Secure Firewall Threat Defense Virtual
Activity Onboard

Create a Decryption Rule with Decrypt - Resign Action

This part of the procedure discusses how to create adecryption policy to decrypt and resign traffic before the traffic reaches the SAML realm. The realm can authenticate traffic only after it has been decrypted.

Procedure

1

If you haven't done so already, log in to the Cisco Security Cloud Control.

2

If you haven't done so already, create an internal certificate authority object to decrypt TLS/SSL traffic as discussed in PKI.

3

Click Policies > FTD Policies.

4

Click Policies > Access Control heading > Decryption.

5

Click New Policy.

6

Enter a Name and choose a Default Action for the policy. Default actions are discussed in Decryption Policy Default Actions.

7

Click Save.

8

Click Add Rule.

9

Enter a Name for the rule.

10

From the Action list, choose Decrypt - Resign.

11

From the with list, choose your service provider certificate object.

12

Click the Applications tab page.

13

In the Available Applications section, enter Azure Authentication Service in the search field.

14

Click Azure Authentication and click Add to Rule.

The following figure shows an example.

15

(Optional.) Set other options as discussed in Decryption Rule Conditions.

16

Click Add.

17

At the top of the page, click Save.

What to do next