Forum Discussion
Nfordhk_66801
Nimbostratus
Jan 23, 2015Using ServerSSL Profiles
Hi,
I am interested in using ServerSSL profiles to secure connectivity from the client to the end host but I have some confusions about the process. Right now our setup looks like this:
Two...
Nfordhk_66801
Nimbostratus
Jan 23, 2015In reality, are there any benefits to letting the F5 perform all these functions? Why not just put certs on the servers themselves and let the F5 acts as a pass through?
- Brad_ParkerJan 23, 2015
Cirrus
If you want to leverage any Layer 7 functionality it will require that the F5 be able to decrypt the SSL traffic. i.e. iRules that use HTTP events. - Nfordhk_66801Jan 26, 2015
Nimbostratus
What about using the ASM? We are purchasing it soon. Will that cause any issues if I just use the F5 as a passthrough? - shaggyJan 26, 2015
Nimbostratus
yes - ASM is Layer 7 functionality. F5 must terminate SSL in order to decrypt client requests, which is required if you want ASM security policies to inspect those requests. So, at a minimum, a client-SSL profile must be assigned to those virtual servers. A ServerSSL profile will re-encrypt traffic back to the pool member.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects