Brainstorming Session: Handling the Performance & Compliance Toll of SSL Decryption on IAG
  

George Fady Lv1Posted 2026-Jun-05 19:50

Let’s talk about a topic that every security engineer wrestles with: SSL Decryption (Man-in-the-Middle & Ingress Client).  
With modern web traffic being almost entirely encrypted via HTTPS, traditional application identification and deep activity auditing are blind without SSL decryption. Sangfor IAG supports robust MITM decryption and Ingress client proxies to expose the contents of these encrypted packets. This allows security modules like application controls or search keyword auditing to work flawlessly.  
But in a production environment with hundreds or thousands of concurrent users, initiating full cryptographic handshakes (handling client/server hellos, certificate validation, and cipher suite selections) puts a massive load on the appliance's CPU resources. Furthermore, it hits a legal grey area regarding user privacy laws (auditing personal emails, financial transactions, etc.).  
Discussion Points for the Community:
  • How do you strike a balance between complete auditing visibility and user privacy? Do you implement strict URL bypass/exclusion rules for financial and healthcare categories?
  • From a hardware perspective, what has been your experience regarding the CPU/memory impact on IAG once SSL Decryption is toggled on?
  • When using the Ingress Client vs. standard MITM approaches, what deployment friction have you experienced on legacy endpoints, and how did you resolve certificate push errors?

Let’s discuss the best practices to keep our networks both secure and high-performing!