Lightboard Lessons: SSL Outbound Visibility

You’ve been having trouble sleeping because of the SSL visibility problem with all the fancy security tools that don’t do decryption. Put down that ambien, because this Lightboard Lesson solves it. In episode, David Holmes diagrams the Right Way (tm) to decrypt and orchestrate outbound SSL traffic, improving SSL visibility, decreasing failures and improving network performance.

Published Jul 06, 2016
Version 1.0
  • From my knowledge you will need the SSL forward proxy license, which is not included in the SWG license as far as i know. You can integrate SWG into the solution, but this is an option. The SSLi solution can also be run without SWG.

     

  • So it is 1 month later. Post Agility. Any update on the licensing information discussed above?

     

  • Great discussion on outbound SSL visibility. You forgot one important option; forwarding of traffic to a cloud-based filter that does everything the devices you mentioned does, in a single pass, and decrypts SSL once to do it. F5 LTM can simply build a GRE tunnel to that cloud service, and without the cost, complexity, and performance hit of distributing across multiple security appliances, or the addition of the SWG module, you have a.) SSL Visibility (even for DLP), b.) Resiliency of the cloud, and c.) Scalability of a cloud security platform that can grow in SSL performance for a reasonable recurring cost, much like you pay on all those security devices sitting in your data center that you backhaul all the traffic to in order to achieve this centralized processing of outbound SSL traffic. Nothing like combining the leader in inbound traffic management and security, with the leader in outbound traffic security in the cloud.

     

  • No problem at all. In fact, mystery answer is probably more fun than actual answer...so well played.

     

  • there will be details coming, and I can't share exactly why, but my licensing information above is probably inaccurate. Hate to be cryptic, but can't give the goods just yet.

     

  • Great vid. Very digestible way of explaining it. Is there a with paper on this kind of set up? Or could you recommend reading material?

     

  • i believe the LTM+SWG licensing combo would be required, yes, but an SE could confirm for you.

     

  • DavisLi's avatar
    DavisLi
    Ret. Employee

    Thanks! Do we still need an LTM module as the SSL Offloader? Assuming we do not have an SSL offload device currently?

     

  • Hi Recontuer! Glad to hear such great feedback. The solutions depicted in this particular lightboard would lean heavily on the forward proxy functionality in the SWG module.
  • DavisLi's avatar
    DavisLi
    Ret. Employee
    Easy to understand explanation! Always loves how F5 explains technology. So, my question is, an LTM module on a powerful enough hardware plus a PEM to service chain will do it? Thanks!