May 18, 2022

TAP service on BIG IP LTM

Hi Guys, its been  a while since I've been working wiht big ip so looking forward to start it now again. Lately I was asked if there is an option of TAPing decrypted traffic on the big ip and mirroring it to the separate interface of the BIGIP from which it will further reach the external IDS for inspection.

From what I see there is a separate 'TAP service' for that in the SSL Orchestrator. 

However what I wonder is if it's doable on the deployment w/o SSL Orchestrator. 

So currently there are 2 implemented options for SSL: passthrough or offloading. The question is if that traffic could be mirrored to a separate interface that will be used as a TAP.  

Thanks in advance for taking your time on that and sharing your experience. thx

