scm_create_decryption_rule
Define decryption policy rules for network traffic in Palo Alto Networks Strata Cloud Manager. Specify source/destination zones, addresses, services, and actions (decrypt or no-decrypt) to control SSL/TLS inspection.
Instructions
Create a decryption policy rule.
Args: name: Unique name for the rule. folder: Folder to create the rule in. action: Decryption action — 'decrypt', 'no-decrypt'. source_zone: List of source zone names. destination_zone: List of destination zone names. source: Source address objects/groups (default ['any']). destination: Destination address objects/groups (default ['any']). service: List of service names (default ['any']). profile: Decryption profile name to apply (optional). description: Optional description. tag: Optional list of tag names. disabled: Whether the rule is disabled (default False). rulebase: Rulebase — 'pre' (default) or 'post'. tsg_id: Optional TSG ID or named alias. Defaults to SCM_TSG_ID.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | ||
| folder | Yes | ||
| action | Yes | ||
| source_zone | Yes | ||
| destination_zone | Yes | ||
| source | No | ||
| destination | No | ||
| service | No | ||
| profile | No | ||
| description | No | ||
| tag | No | ||
| disabled | No | ||
| rulebase | No | pre | |
| tsg_id | No |