Overview of the following enhancements in SonicOS 6.5.2 for Decryption Services:
It allows you to enable DPI-SSL on a per-zone basis rather than globally. You can enable both DPI-SSL Client and DPI-SSL Server per zone.
You can navigate to Manage | Network | Zones and click on the configure button on the zone and go to the General tab.
DPI-SSL for both client and server can now be controlled by Access Rules.
You can navigate to Manage | Rules | Access Rules and click on the configure button on the appropriate access rule and go to the Advanced tab.
Previously, DPI-SSL Client supported only RSA-related ciphers, such as TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256. DPI-SSL Client now supports ECDSA (Elliptic Curve Digital Signature Algorithm) ciphers:
TLS_ECDHE_ECDSA_WIATH_AES_128_GCM_SHA256
TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256
