Forum Discussion
Using ServerSSL Profiles
Passthrough and ASM:
For any intelligent use of ASM, you need to have visibility to Layer 7 traffic on the client requests (and responses).
In case of ssl encrypted traffic from the clients, you need to terminate the client ssl connection at the BIG-IP for the ASM to be able to see the Layer 7 traffic - and function as an application level firewall/protection device. You can the re-encrypt the traffic at the server side of the BIG-IP to the servers if required. Return traffic goes just the reverse.
If you just do the passthrough without ssl termination at the BIG-IP, the ASM cannot see Layer 7 stuff and you could as well revert to use normal L2-4 firewall instead of the ASM application level firewall.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com