Most web traffic is now encrypted. That is good for privacy and awkward for any firewall that relies on reading content: without decryption, intrusion prevention, anti-malware and URL filtering see a hostname and a certificate, and little else. TLS inspection fixes that. Done carelessly, it also breaks applications, slows the network and decrypts things nobody should be reading.
What inspection actually does
The firewall places itself in the middle of the connection. It completes the encrypted session with the website, opens a second one with the user's browser using a certificate it issues on the spot, and inspects the traffic between the two. For that to work without warnings, every device has to trust the firewall's certificate authority.
That makes inspection a managed-device feature. You can push the certificate to company laptops through Group Policy, Intune or another device-management tool. You cannot push it to a visitor's phone, which is one reason guests belong in their own zone.
TLS 1.3 encrypts more of the handshake than earlier versions, including the server's certificate, so a firewall that only reads handshakes sees less than it used to. Current next-generation firewalls can inspect TLS 1.3 fully. Older models and older firmware may not, which is worth checking before you plan around it.
What to decrypt
- General web browsing and uncategorised sites, where phishing pages and drive-by downloads arrive.
- File downloads, so anti-malware and sandboxing see the file rather than an encrypted stream.
- Webmail and file-sharing services you allow but do not manage, where data can leave as easily as it arrives.
- Newly registered and low-reputation domains, if the firewall categorises them.
What to leave alone
- Banking, health and similar personal categories. Staff use work devices for personal errands. Reading those sessions creates sensitive personal data you then have to protect, which is why vendors generally recommend exempting them.
- Applications that pin their certificates, such as some banking apps, messaging apps and update agents. They reject the firewall's certificate by design. The fix is an exemption, not a workaround.
- Services your vendors tell you not to inspect. Microsoft, for example, publishes Microsoft 365 endpoints it recommends sending without break-and-inspect.
- Anything your policy does not yet cover. Inspection of staff traffic belongs in the acceptable-use policy, and staff should be told before it is switched on.
Privacy and the DPDP Act
Decrypted traffic contains personal data: names, messages, and sometimes financial or health details. Under the Digital Personal Data Protection Act that data needs a purpose, limits and protection like any other personal data you hold. In practice that means a written inspection policy, exemptions for personal categories, logs that record verdicts rather than content wherever the firewall allows it, and access to those logs limited to the people who need it. This is infrastructure guidance, not legal advice; our DPDP readiness work covers the infrastructure side.
Size for inspection, not for the headline
Decryption is expensive. Firewall datasheets list several throughput figures, and the largest is usually plain firewall throughput with nothing inspected. The figure that matters here is the one for threat protection or SSL/TLS inspection, which on many models is a small fraction of the headline. Size against that number at your actual internet bandwidth, with room to grow. We cover the rest of that check in before you sign the firewall renewal.
Rolling it out without breaking things
- Deploy the certificate to managed devices and confirm every browser in use trusts it, including Firefox, which may need a policy to use the system certificate store.
- Enable inspection for the IT team first, then one department, with failures logged.
- Read the failure log daily for the first week. Add exemptions for what breaks, by application or domain, never by switching inspection off for a whole group.
- Widen to everyone, then review the exemption list every quarter. Exemptions accumulate like firewall rules.