When accessing applications that require client certificate authentication—commonly known as Mutual TLS (mTLS)—traffic passing through an SSL Visibility (SSLV) appliance may fail. Symptoms include the browser spinning indefinitely, "site cannot be reached" errors, and missing server-side acknowledgements (ACKs) in packet captures. This occurs because the SSLV appliance cannot re-present the client's private certificate during the decryption/inspection process.
SSL Visibility appliances do not support decryption of mTLS traffic. During the SSL handshake, the server requests a client certificate. If the SSLV is configured to inspect the flow, it breaks the certificate chain because it does not have access to the client’s private key to re-sign or re-present the certificate to the origin server.
To allow mTLS traffic to function correctly, configure a policy rule to bypass inspection for the affected destinations.
If the issue persists, please see . Scroll to the bottom of the page and click on your respective region to speak with a Support Engineer.