Hello Smith Oliver,
For Decryption Port Mirroring, first verify that the interface connected to the network TAP is explicitly configured as the mirror destination for decrypted traffic and not for the original encrypted session stream. Missing decrypted captures typically occur when SSL/TLS decryption is working, but the decryption profile is not associated with the mirroring configuration or the wrong egress interface is selected.
Confirm that the mirror interface is operational, assigned to the correct virtual system or context if applicable, and that no security policies, VLAN tagging mismatches, or MTU issues are preventing the mirrored packets from reaching the capture appliance. It is also important to verify that the device is successfully generating decrypted sessions in its session table, because Decryption Port Mirroring only exports traffic that has actually been decrypted. Review the decryption logs and session details to confirm successful certificate validation and active decryption before checking the mirror output. Finally, perform a packet capture directly on the mirror interface and compare it with captures from the TAP tool to determine whether the issue is with the mirroring configuration or with the downstream monitoring platform receiving the traffic.
If my answer is useful for you, please hit Accept the answer for me please.
HL.