TLS inspection: what to decrypt and what to leave alone

By the NexusSec team · 5 min read · Published October 2026
Short version: Decrypt general web browsing and file downloads, where phishing and malware arrive. Exempt banking, health and other personal categories, applications that pin their certificates, and services your vendors say not to inspect. Deploy the firewall's certificate to managed devices first, roll out one group at a time, and size the firewall for its inspection throughput rather than its headline figure.

Most web traffic is now encrypted. That is good for privacy and awkward for any firewall that relies on reading content: without decryption, intrusion prevention, anti-malware and URL filtering see a hostname and a certificate, and little else. TLS inspection fixes that. Done carelessly, it also breaks applications, slows the network and decrypts things nobody should be reading.

What inspection actually does

The firewall places itself in the middle of the connection. It completes the encrypted session with the website, opens a second one with the user's browser using a certificate it issues on the spot, and inspects the traffic between the two. For that to work without warnings, every device has to trust the firewall's certificate authority.

That makes inspection a managed-device feature. You can push the certificate to company laptops through Group Policy, Intune or another device-management tool. You cannot push it to a visitor's phone, which is one reason guests belong in their own zone.

TLS 1.3 encrypts more of the handshake than earlier versions, including the server's certificate, so a firewall that only reads handshakes sees less than it used to. Current next-generation firewalls can inspect TLS 1.3 fully. Older models and older firmware may not, which is worth checking before you plan around it.

What to decrypt

What to leave alone

Privacy and the DPDP Act

Decrypted traffic contains personal data: names, messages, and sometimes financial or health details. Under the Digital Personal Data Protection Act that data needs a purpose, limits and protection like any other personal data you hold. In practice that means a written inspection policy, exemptions for personal categories, logs that record verdicts rather than content wherever the firewall allows it, and access to those logs limited to the people who need it. This is infrastructure guidance, not legal advice; our DPDP readiness work covers the infrastructure side.

Size for inspection, not for the headline

Decryption is expensive. Firewall datasheets list several throughput figures, and the largest is usually plain firewall throughput with nothing inspected. The figure that matters here is the one for threat protection or SSL/TLS inspection, which on many models is a small fraction of the headline. Size against that number at your actual internet bandwidth, with room to grow. We cover the rest of that check in before you sign the firewall renewal.

Rolling it out without breaking things

  1. Deploy the certificate to managed devices and confirm every browser in use trusts it, including Firefox, which may need a policy to use the system certificate store.
  2. Enable inspection for the IT team first, then one department, with failures logged.
  3. Read the failure log daily for the first week. Add exemptions for what breaks, by application or domain, never by switching inspection off for a whole group.
  4. Widen to everyone, then review the exemption list every quarter. Exemptions accumulate like firewall rules.

Frequently asked questions

Do we need to tell staff about TLS inspection?

Yes. Put it in the acceptable-use policy and tell staff before it goes live, with personal categories such as banking and health exempted. Take legal advice on your specific obligations; we advise on the technical side.

Will TLS inspection slow our internet down?

It can, if the firewall was sized for its headline throughput rather than its inspection throughput. Sized correctly, users should not notice it.

Can we inspect guest Wi-Fi?

Not without certificate warnings, because guest devices do not trust your certificate authority. Keep guests in their own zone with DNS and URL filtering, which works without decryption.

Why does an application stop working once inspection is on?

Usually because it pins its certificate and rejects the firewall's. Add an exemption for that application's domains rather than disabling inspection.

Planning to switch on TLS inspection?

We check the firewall is sized for it, write the exemption list with you, and roll it out by group so nothing breaks on the first morning.

Book a free consultation