Forum Discussion
F5 SSL Pass-through with Xforward.
I am having an LTM which load balance the traffic to two WAF clusters, these clusters are located in differenct locations within the same enviorment (Kind of HA setup within the same site), we relay in the LTM to do the load balancing, noting that these WAF clusters are sperated by L3 firewalls, so i cant extend the IP addressing schema to both of them.
Please find the reasons for why i want to use the SSL-passthrough:
- The client want to maintain the SSL decryption in the WAF devices for security reasons, the LTM devices are not part of thier secure enviorment.
- We are having some issue with the CN of the certifcate when it is installed in these different in the WAF devices coz it is tighed with an IP address (it is an internal service), this is where SSL bridging is failing.
- Finally the client cant make routing changes and he need to see the client IP address, this why i need to insert the Xforward coz installing the LTM in routed mode is not an option.
This is it is a bit complex implentation, for this reason the only solution was for me to do the SSL passthrough.
I am still confused about a point if the SSL-Passtrhough is still performing any kind of SSL decryption when it is on the way between the SSL client and the SSL server?
i mean does the BIG-IP system to decrypt, optimize, and reencrypt the SSL traffic whith the SSL passthrough or not coz i think it impossible to insert the Xforward without doint this?
Thanks again for your help.
Correct, the LTM has to decrypt the traffic to insert the x-forwarded-for header. There is no way around that.
If you have a requirement that the LTM does not decrypt the traffic, it will be impossible to insert an x-forwarded-for header. These two client requirements are mutually exclusive.
"Proxy SSL Passthrough" is not the same thing as simple "SSL Passthrough." Proxy SSL Passthrough does decrypt the traffic as long as a compatible cipher suite is negotiated between client and server, and falls back to SSL Passthrough when DH/DHE ciphers are negotiated.
- MuhannadMar 09, 2020Cirrus
I think this is very clear for me now.
I will let the client take the decision, thanks Seteve for the help.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com