Forum Discussion

Lazar_92526's avatar
Lazar_92526
Icon for Nimbostratus rankNimbostratus
Mar 21, 2013

UAG and F5 SSL communication

Current designing and wondering if there is anything we may need to consider regarding passing SSL traffic to Microsoft's UAG.

 

 

If we use the F5 to do unencrypting and re-encrytping of the packet, will UAG react different to that packet?

 

I'm investigating doing a SSL re-encryption, which is contrary to the design that is currently being looked at. Right now, the design consideration is to do SSL passthrough all the way to UAG, and that would limit our ability to inspect and know what is going on from a security packet inspection.

 

 

Looking for guidance

 

  • Ryan_Korock_46's avatar
    Ryan_Korock_46
    Historic F5 Account
    Not sure what you visibility decrypting/re-encrypting would get you. I believe it's IPSEC traffic that then gets encrypted (again) via SSL.
  • If this might help, we have been doing tests lately using decryption/encryption all the way without issues.

     

    setup is client => ssl =>uag vip => ssl => uag servers =>ssl=> sharepoint vip =>ssl => sharepoint servers