Implementing SSL Orchestrator - Management with BIG-IQ
Introduction This article is part of a series on implementing BIG-IP SSL Orchestrator. It includes high availability and central management with BIG-IQ. Implementing SSL/TLS Decryption is not a tri...
Published Jan 21, 2020
Version 1.0KevinGallaugher
Employee
Technical Marketing Engineer for SSL Orchestrator. I have over 20 years experience in Cybersecurity, with over 10 years spent as a Technical Marketing Engineer. Prior to F5 Networks I worked at Blue Coat, Gigamon and Fortinet.KevinGallaugher
Employee
Technical Marketing Engineer for SSL Orchestrator. I have over 20 years experience in Cybersecurity, with over 10 years spent as a Technical Marketing Engineer. Prior to F5 Networks I worked at Blue Coat, Gigamon and Fortinet.Romain
Employee
Feb 05, 2020Piotr,
About (2) above and the import process, the BIG-IQ ensures that the base SSLO feature configuration is done on the BIG-IP. This includes the NTP, Default Route, and DNS configurations that the administrator does when first enabling SSLO on the BIG-IP. In the case of this lab iirc, these values are already set on the BIG-IP. On blank devices freshly added to the network, these values can be set during the discovery process with this mechanism.
So, the result is that changes can be made to the BIG-IP configuration in the process. No topology is "deployed" to the BIG-IP. HTH.
Romain