Do you mean terminate an external connection to the mesh using TLS? I think you probably want the istio ingress gateway, with TLS configured with your certificates:
Istio configures envoyas a gateway for you in this scenario (you don’t need to specify the envoy config)