Forum Discussion
F5 SSL-O service chaining issue
This is by design. Encrypted traffic does not flow to ICAP and HTTP services, which includes SWG.
Dear Kevin
But i don't understand, why i juse classification by source IP and bypass ssl. It can be sent to SWG
- Nikoolayy1Aug 26, 2022MVP
Also I forgot to mention that if you have URL database the SSLO can also do a URL lookup based on CN or SNI without SSL decryption and you can then forward those sites to the the proxy with a service as mentioned that is not HTTP or ICAP. You can also create a custom categories without license. Also you should be able to use the category lookup as a condition rule without directly changing that Per-Request Policy as the Guided config will change it.
Category lookup
An example:
Managing the URL Category Database
https://clouddocs.f5.com/sslo-deployment-guide/chapter4/page4.8.html
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com