you cando ssl proxy with squid also i think - you run it and grab cert for your browsers, put your bank on bump list and have viz for siem - i still have to do this, is is a bit gray hat, not really but you do need to think about it and be judicious, it is industry standard best practice if you want to look at it objectively (widely used) , it lives on the edge is basically transparent. a good upgrade for malcolm box, can be cpu intensive if you have a busy network - you have to offer this to clients #pkt cap #dpi #flavors of tls #open source #newsgroups



