For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Chandan_Viswesw's avatar
Chandan_Viswesw
Icon for Nimbostratus rankNimbostratus
Jul 31, 2014

Concerns over F5 Load balancer's co-existence with IronPort ESAs

Planning to put a F5 load balancer in front of IronPort ESAs to spread the SMTP traffic from internet. We have couple of concerns.

 

  1. Can the SSL acceleration feature in the F5 be turned off? Apparently, the TLS communication between internet source and IronPort server will be interrupted due to this feature.

     

  2. Is F5 load balancer "session aware"? I mean, does it forcefully disable/disconnect a session between source and destination (IronPort) for any reason?

     

1 Reply

    1. Yes, just don't apply an ssl profile to the virtual server(client or server)

       

    2. Without ssl termination, which as stated above you want to disable, the f5 won't be aware of anything except the layer 4 tcp conncetions. It would not be able to make any determinations or take any actions based on message content. The only reason I can think of that it would disconnect/disable would be due to standard tcp/ip failures, or if a pool member fails(influenced by your 'action on service down' setting)