> When the client sends a hello, the firewall says “that looks like a TLS hello”, and then waits for the server’s response. It inspects the certificate and then applies any rules.<p>This kind of stuff is exactly why TLS 1.3 encrypts <i>everything</i> now.