ZIA: Audit SSL Inspection Bypass
Keywords
ssl inspection, ssl bypass, do not inspect, do not decrypt, ssl exceptions, ssl audit, ssl security gap, bypass ssl, inspection exclusion, ssl policy review, certificate pinning, decryption mode
Overview
Audit ZIA SSL inspection rules to understand what traffic is being inspected, bypassed, or blocked at the SSL layer. This skill works exclusively with SSL inspection tools. It does NOT call URL filtering, DLP, or other unrelated tools unless the user explicitly asks for cross-referencing.
Use this skill when: A security administrator wants to review SSL inspection rules, understand what traffic is or is not being decrypted, or audit SSL inspection policy configuration.
Scope Boundaries
ONLY use these tools in this skill:
zia_list_ssl_inspection_rules()-- primary toolzia_get_ssl_inspection_rule(rule_id)-- detail for a specific ruleget_zia_user_groups(search)-- resolve group IDs referenced in SSL rulesget_zia_user_departments(search)-- resolve department IDs referenced in SSL ruleszia_list_locations()-- resolve location IDs referenced in SSL rules
DO NOT call these tools unless the user explicitly asks:
zia_list_url_filtering_rules()-- not part of SSL inspection auditzia_list_web_dlp_rules()/zia_list_web_dlp_rules_lite()-- not part of SSL inspection auditzia_list_firewall_rules()-- not part of SSL inspection audit- Any other non-SSL tool
Workflow
Follow this 4-step process.

