Forum Discussion
F5 BigIP + TAP NetworkCritical + Fraud Detetion
Hi đź‘‹
From the past days I have been struggling with a weird problem.
We have been migrating some web servers from HAProxy to the BigIP LTM.
The migration it's straightforward, BigIP make de SSL termination to the client and use the respective Pool to the App servers.
We have a solution that need to receive the same traffic (between the client and BigIP), and we are using a TAP device to SPAN all the traffic. The same traffic are been delivery to the TAP encrypted.
In the other end the TAP delivery that traffic to a Fraud Detection solution, that have the ability to decrypt the traffic and run some signatures.
The weird behaviour is from the Fraud Detection solution, it's not say that is unable to decrypt the traffic, but not process any traffic from the BigIP. If we switch back to the HAProxy web server's everything works. Both BigIP and HAProxy are using the same public and private key. We have compared some tcpdumps and don't see any difference between TLS protocol or cipher that are been negotiated.
Any ideia if BigIP change something in the traffic?
Thanks
TP
- Jeffrey_GranierEmployee
I think we will need some more details about the Fraud Detection solution not being able to process any traffic. Are there certain rules/settings that the Fraud Detection expect traffic to come from and will only process based off that rule? Like source mac? source IP? There are a a number of changes in the traffic when it passes through a BIG-IP depending upon the configuration. The virtual server configuration offers address translation as well as port translation. Can you provide more info
- tpimpaoAltostratus
Hi Jeffrey!
We have found the issue, was nothing about F5 but was a limitation in our Fraud Detection solution. We have to disable the "extended master secret extension" (https://my.f5.com/manage/s/article/K66202244 ).Thanks
TP
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com