DESCRIPTION:
The Client DPI-SSL deployment scenario typically is used to inspect HTTPS traffic when clients on the LAN browse content located on the WAN. In this scenario, the firewall typically does not own the certificates and private keys for the content it is inspecting. After performing DPI-SSL inspection, the appliance re-writes the certificate sent by the remote server and signs this newly generated certificate with the certificate specified in the Client DPI-SSL configuration. By default, this is the firewall certificate authority (CA) certificate, but a different certificate can be specified. Users should be instructed to add the certificate to their browser’s trusted list to avoid certificate trust errors.
To import the certificate into a browser, perform the following:
- Internet Explorer: Go to Tools | Internet Options, click the Content tab and click Certificates.
Click the Trusted Root Certification Authorities tab and click Import. The Certificate Import
Wizard will guide you through importing the certificate.
Chrome: Go to Settings | Advanced | Manage Certificates. Select the tab Trusted Root Certification Authorities and click Import. Browse for the DPI-SSL Certificate and place it in the Trusted Root store. Once complete close the browser and re-launch. Depending on the operating system a restart may be required.
Referenced from URL: https://www.sonicwall.com/support/knowledge-base/how-to-install-the-dpi-ssl-certificate-in-modern-browsers/171003152237302/