For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

DP's avatar
DP
Icon for Nimbostratus rankNimbostratus
Jun 26, 2015

SSL Termination and SNAT

Hi.

 

It is possible to have a VS with an SSL profile and SNAT disabled? This is so the client IP will appear as the source address on the web server as opposed to the f5's floating IP.

 

Ultimately I'd like to place an IPS between the f5 and the web servers to inspect decrypted HTTP traffic.

 

Without SNAT disabled, the IPS will potentially block all f5 traffic to the web servers as it sees the source IP as the f5's floating IP. Unfortunately the IPS can't apply a action (block or allow) using the X-Forwarded-For header as the source IP.

 

Thanks.

 

1 Reply

  • 1) "It is possible to have a VS with an SSL profile and SNAT disabled?

     

    • Yep. You do not have to offload SSL in F5 to apply IP-address translations. Also you can have SSL offload enabled while SNAT is disabled, you will just have to make sure you will not run into asymetric routing issues by doing that.

    2) "Without SNAT disabled, the IPS will potentially block all f5 traffic to the web servers as it sees the source IP as the f5's floating IP."

     

    • Is this an assumption, or have you tested it? All modern WAF/IPS/IDS systems are expected to work regardless of the source IP address of an incoming request. If your requests are getting blocked in "IPS Device" after you apply SNAT, it' because of an IP-based whitelist or poorly managed IPS profile.