Forum Discussion
SSL Termination and SNAT
Hi.
It is possible to have a VS with an SSL profile and SNAT disabled? This is so the client IP will appear as the source address on the web server as opposed to the f5's floating IP.
Ultimately I'd like to place an IPS between the f5 and the web servers to inspect decrypted HTTP traffic.
Without SNAT disabled, the IPS will potentially block all f5 traffic to the web servers as it sees the source IP as the f5's floating IP. Unfortunately the IPS can't apply a action (block or allow) using the X-Forwarded-For header as the source IP.
Thanks.
1 Reply
- Hannes_Rapp
Nimbostratus
1) "It is possible to have a VS with an SSL profile and SNAT disabled?
- Yep. You do not have to offload SSL in F5 to apply IP-address translations. Also you can have SSL offload enabled while SNAT is disabled, you will just have to make sure you will not run into asymetric routing issues by doing that.
2) "Without SNAT disabled, the IPS will potentially block all f5 traffic to the web servers as it sees the source IP as the f5's floating IP."
- Is this an assumption, or have you tested it? All modern WAF/IPS/IDS systems are expected to work regardless of the source IP address of an incoming request. If your requests are getting blocked in "IPS Device" after you apply SNAT, it' because of an IP-based whitelist or poorly managed IPS profile.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
