Forum Discussion
wayney_128269
Nimbostratus
Oct 28, 2009security concern about BIGIP SSL connection
I have a concern about BIGIP connections.
Here is the scenario, if User A authenticates using NTLM to a web service behind a BIGIP VIP via SSL, can another user re-use an authenticated connection that already exists on the BIGIP to the same server? User A's client app passes a cookie to the server to maintain session persistence so that NTLM can occur properly.
User A > BIGIP > Connection A on BIGIP to Server XYZ
User B > BIGIP > Can User B use the same Connection A already on the BIGIP to connect to Server XYZ?
thanks
- The_Bhattman
Nimbostratus
It's possible for user B to use the same connection but user B would most likely be in a separate session. One of the ways to strengthen up the communication is to basically have a SSL connection between Client ---> BIGIP --> Server. This way you have end to end encryption. - hoolio
Cirrostratus
dupe - hoolio
Cirrostratus
That is a legitimate concern. In pre-v10 you can set a /32 mask on the OneConnect profile to ensure that the serverside TCP connection is only re-used for the same client IP address. In pre-v10, if you have multiple clients connecting from the same IP address to an app that uses NTLM, it would probably be best to not use OneConnect on the VIP.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects