# Decrypt ssl server

**URL:** <https://community.f5.com/t/decrypt-ssl-server/75692>\
**Category:** Technical Forums\
**Tags:** application-delivery\
**Created:** [January 31, 2025, 5:18am UTC](https://community.f5.com/t/decrypt-ssl-server/75692 "2025-01-31T05:18:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anzine321](https://avatars.discourse-cdn.com/v4/letter/a/87869e/32.png) [@Anzine321](https://community.f5.com/u/Anzine321)\
**Post date:** [January 31, 2025, 5:18am UTC](https://community.f5.com/t/decrypt-ssl-server/75692/1 "2025-01-31T05:18:11Z")

</div>

Hi everyone  
Is it possible to decrypt ssl server profile?

I want to view data send from server to f5

---

<div class="post-metadata">

**Author:** ![Michael\_Saleem](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/michael_saleem/32/7239_2.png) [@Michael\_Saleem](https://community.f5.com/u/Michael_Saleem)\
**Post date:** [January 31, 2025, 9:14am UTC](https://community.f5.com/t/decrypt-ssl-server/75692/2 "2025-01-31T09:14:59Z")

</div>

Yes, it is possible. If you’re on version 15 or higher, you can follow the instructions in the below F5 article:

> **[myF5](https://my.f5.com/manage/s/article/K31793632)**

Because you stated that you want to decrypt the traffic on the server-side (i.e. between the BIG-IP and the back-end pool member), you will need to use the “p” flag in your tcpdump command (this is mentioned in the same article).

An example of the command that I personally most often use is:

```bash
tcpdump -i <VLAN>:p -nn -s0 --f5 ssl "host <CLIENT IP> and port 443" -w /var/tmp/"$HOSTNAME"_"$(date +%d-%m-%y)".pcap

```

---

<div class="post-metadata">

**Author:** ![Juergen\_Mang](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/juergen_mang/32/12756_2.png) [@Juergen\_Mang](https://community.f5.com/u/Juergen_Mang)\
**Post date:** [January 31, 2025, 1:54pm UTC](https://community.f5.com/t/decrypt-ssl-server/75692/3 "2025-01-31T13:54:02Z")

</div>

You can use my script: [GitHub - JuergenMang/f5-tls-decrypt: Creates the Pre Master Secret File from tcpdump with enabled f5 sslprovider to decrypt TLS encrypted traffic with Wireshark · GitHub](https://github.com/JuergenMang/f5-tls-decrypt)
