Skip to main content
abarushka
Staff
Staff
January 8, 2020

Technical Tip: How to sniff unencrypted mirrored TLS traffic without connecting PC to physical port

  • January 8, 2020
  • 0 replies
  • 2287 views
Description
This article describes how to sniff unencrypted mirrored TLS traffic without connecting PC to physical port.

Solution
Note that decrypting TLS traffic may expose sensitive information.

Configure TLS port mirroring under firewall policy for specific port.





Open SSH connection using SSH client, log the session and run in CLI:
# diagnose sniffer packet port4 (port defined under firewall policy e.g) '6 0 a'.
The above command with return unencrypted TLS traffic.