When you enable the DPI-SSL services on your SonicWall network security appliance, the clients behind the firewalls that have no related certificates are often required to confirm by going through HTTPS web pages. Otherwise, users have to install the corresponding DPI-SSL certificates manually if they want to bypass this step, by downloading the corresponding certificate, and then installing it.
To simplify the procedure so that clients can download and install the certificates automatically, DPI-SSL enforcement is necessary.
NOTE:Â DPI SSL enforcement is a licensed service and is automatically activated if Capture Client is licensed on the firewall. The count remains the same as per the node count of Capture Client endpoints. DPI SSL enforcement is done with the help of the Capture Client.
Navigate to MANAGE | Security Services | DPI SSL enforcement tab to configure this section.

This enforcement can also be done on a zone level similar to Client AV and Client CF enforcement.


When the devices present behind this zone try to go online, they will be asked to install the Capture Client if they do not have the DPI SSL certificate installed.
It is best to use the 'DPI-SSL Enforcement List' and 'Excluded from DPI-SSL Enforcement List' to make sure that this is not enforced on unnecessary end machines like phones, printers etc. The DPI-SSL Enforcement section contains the lists of addresses included in and excluded from DPI-SSLÂ enforcement.


When a non-complaint endpoint (a machine that does not have the DPI SSL certificate installed) tries to go online, the following message shows up.

Once you click on install, Capture Client is installed which in turn installs the DPI SSL certificate on the end client as per the policy that gets applied from CMC.
