SSL Orchestration: Making outbound SSL inspection faster and more resilient
It's an awesome article and thanks a lot for posting it. Can you please guide us few things- 1. Lets take an example SSLO is being used in Forward proxy mode and sitting in transparent mode. Cases require Client Authentication request by external server, how does SSLO participate in that part of communication?
-
In a multi-link environment, how does SSLO maintain the link affinity after Decrypt/encrypt processing and inline server chain processing? Do you rely on VLAN Tagging techniques whenever traffic enters on the SSLO appliance?
-
For reverse proxy environment where client wants to place SSLO just for traffic decrypt/encrypt and inline service chaining to multiple tools, Can it support ephemeral ciphers ? Some of the old blogs state that only Static Key ciphers supported in the reverse proxy mode. Can you please explain why.
Thanks Raj