Forum Discussion
Siddharth_Gupta
Nimbostratus
Nov 30, 2006SSL enabling towards Internet
Hi,
I want to know if its possible for the LTM to terminate HTTPS on the client side, redirect the unencrypted HTTP to a pool of HTTP proxies and re-enable SSL on the way out to the internet.
So the flow should look like this....
Client----(HTTPS)----LTM--------(HTTP)-----HTTP Proxy------(HTTP)------LTM ------(HTTPS)-------Internet
I need this since my HTTP proxies are incapable of processing HTTPS traffic.
Please advise.
- Chad_Roberts_21
Nimbostratus
That's actually the default scenario. If you enable SSL on the client side, but then you simply configure the pool members to respond on whatever port they listen on (80, for example), it will decrypt the traffic and forward it unencrypted to the pool members. You would actually have to configure another SSL profile for the server side if you wanted it encrypted between the F5's and the pool members as well. - Siddharth_Gupta
Nimbostratus
The problem is that none of my pool members are the actual servers. They are just http proxies. So the server resides in the Internet and hence I cannot enable Server side SSL on the F5 towards my pool members. - hoolio
Cirrostratus
That actually isn't clear. Can you elaborate on exactly what you're trying to accomplish? - Siddharth_Gupta
Nimbostratus
Yes I want to decrypt the traffic to the HTTP proxy, but have the BIG-IP re-encrypt it somehow after the proxy to the final web server. - Chad_Roberts_21
Nimbostratus
Is the purpose of this science project just to be able to inspect all of the HTTP traffic at the proxy? Why not just use a proxy that has the ability to decrypt SSL traffic, inspect it, and then re-encrypt it all by itself? (I think some vendors call that "SSL interception") What is this design aimed to accomplish that the other would not? - Siddharth_Gupta
Nimbostratus
The purpose is to inspect both HTTP and HTTPS websites for adult content and redirect adult websites to a "Access not allowed" web page. The current HTTP proxies are incapable of handling encrypted traffic. So I need a design wherein the proxies process only http traffic and the F5 takes care of decryption and re-encryption.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects