Skip to main content

Enabling Client-to-Proxy mTLS

Client-to-Proxy mTLS ensures that users must present a valid certificate to the Threat Protection proxy before traffic is allowed through.

Steps

  1. Open Traffic Configuration for the relevant HTTP proxy.
  2. Scroll to the Mutual TLS (mTLS) section.
  3. Toggle mTLS Client to Proxy to On position.
  4. Under Configure Trust Store:

  - Select one or more previously uploaded CA certificates from the dropdown menu

  - Click Add

Note: You can select up to 5 CA certificates for client validation.

  1. Check CRL Validation status.

  - Ensure CRL Validation is enabled if you require real-time revocation checking.

Result

  • Only clients presenting valid certificates issued by trusted CAs are allowed access.