Mutual TLS (mTLS) traffic fails through SSL Visibility Appliance
search cancel

Mutual TLS (mTLS) traffic fails through SSL Visibility Appliance

book

Article ID: 443539

calendar_today

Updated On:

Products

ISG SSLV

Issue/Introduction

When accessing applications that require client certificate authentication—commonly known as Mutual TLS (mTLS)—traffic passing through an SSL Visibility (SSLV) appliance may fail. Symptoms include the browser spinning indefinitely, "site cannot be reached" errors, and missing server-side acknowledgements (ACKs) in packet captures. This occurs because the SSLV appliance cannot re-present the client's private certificate during the decryption/inspection process.

Environment

  • Product: ISG SSLV SV-Enterprise
  • Version: 5.x and higher
  • Feature: Mutual TLS (mTLS) / Client Certificate Authentication

Cause

SSL Visibility appliances do not support decryption of mTLS traffic. During the SSL handshake, the server requests a client certificate. If the SSLV is configured to inspect the flow, it breaks the certificate chain because it does not have access to the client’s private key to re-sign or re-present the certificate to the origin server.

Resolution

To allow mTLS traffic to function correctly, configure a policy rule to bypass inspection for the affected destinations.

  1. Log in to the SSL Visibility Management Console.
  2. Navigate to Policy > Rules.
  3. Create a new rule for the specific destination IP or URL/Domain.
  4. Set the Action to Cut Through.
  5. Move the rule to a high-priority position in the policy list to ensure it triggers before any broad decryption rules.
  6. Apply and commit the policy changes.
  7. Verify the handshake completes successfully by testing the application.

 

Additional Information

If the issue persists, please see Contact Support. Scroll to the bottom of the page and click on your respective region to speak with a Support Engineer.