Non-TLS or non-HTTP traffic will not match the rule that specifies the URLs,
but you can create other rules for evaluating that traffic.
- Create a WebGroup based on URLs for which you want traffic assessed. Create a WebGroup
- Create a Distributed Cloud Firewall egress rule, with the following options:
- Select the URL WebGroup to associate with the rule.
- Enable the TLS Decryption option on the rule.
- Select either TCP or Any for the protocol.
- Upload your own valid CA certificate to Aviatrix PaaS.
- The certificate must be trusted by all the virtual machines on the source SmartGroup you selected for the egress rule.