Security considerations for TLS inspection

You must carefully consider security precautions when using TLS Inspection.

The TLS communications mediated by the Engine are decrypted for inspection, and the private keys of the servers are stored in the TLS Credentials elements on the SMCaaS Application. For these reasons, you must carefully consider security precautions when using TLS inspection. The following recommendations are general guidelines for ensuring the security of the Engine and the SMCaaS Application:

  • Disable SSH access to the Engine’s command line if it is not needed regularly.
  • Make sure that the Engine’s Control IP address is in a protected network.