Skip to main content

Enabling Client-to-Proxy mTLS

Client-to-Proxy mTLS ensures that users must present a valid certificate to the Threat Protection proxy before traffic is allowed through.

Steps​

  1. Open Traffic Configuration for the relevant HTTP proxy.
  2. Scroll to the Mutual TLS (mTLS) section.
  3. Toggle mTLS Client to Proxy to On position.
  4. Under Configure Trust Store:

  - Select one or more previously uploaded CA certificates from the dropdown menu

  - Click Add

Note: You can select up to 5 CA certificates for client validation.

  1. Check CRL Validation status.

  - Ensure CRL Validation is enabled if you require real-time revocation checking.

Result​

  • Only clients presenting valid certificates issued by trusted CAs are allowed access.