Skip to main content

Overview

Mutual TLS (mTLS) provides strong, certificate-based authentication by requiring both parties in a TLS connection to verify each other’s identity. Within the context of Threat Protection, mTLS helps enforce a zero-trust architecture by ensuring only trusted clients and servers can exchange traffic.

Supported mTLS Flows

Threat Protection supports mTLS in two directions:

  • Client to Proxy (Downstream)  Clients must present a valid certificate before traffic is allowed.

  • Proxy to Server (Upstream)  The proxy authenticates itself to your backend server and optionally validates the backend’s identity.

Prerequisites

Before configuring mTLS, ensure:

  • mTLS is enabled on your account
  • You have the required CA and identity certificates

Note: mTLS must be enabled on your account by Threat Protection support. Contact the support team on support@baffinbay.com to enable this feature.