Forum Discussion
Lazar_92526
Nimbostratus
Mar 21, 2013SSL packet and the effects of using SSL Bridging
All,
I'm trying to understand what are the effects on a TCP packet when SSL bridging is performed on it utilizing an LTM. If the SSL is decrypted and then re-encrypted to a backend server...
Kevin_Stewart
Employee
Mar 21, 2013The TCP packet itself should have no bearing on the UAG server, however the SSL may, depending on what you need the SSL for. The big question, IMO, is what are you doing with UAG that requires re-encrypting the traffic? Is it for client certificate authentication?
There are a few options:
1. SSL pass through - it gets the job done, but as you point out, limits your visibility and also limits your ability to persist on the connections.
2. ProxySSL - this would allow you to do an SSL man-in-the-middle - SSL negotiation between the client and server with visibility inside the payload.
3. Question the reason for UAG in the first place. Assuming you're using it for authentication, consider what APM can provide (as in nearly identical functionality, but faster).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects