Technical Articles
F5 SMEs share good practice.
cancel
Showing results for 
Search instead for 
Did you mean: 
KevinGallaugher
F5 Employee
F5 Employee

Introduction

SSL Orchestrator centralizes & manages decryption of SSL/TLS traffic.  This enables security and monitoring tools to view the decrypted content and analyze it for threats and other anomalies.  SSL Orchestrator removes the burden of decrypting content from your security tools so they perform better and are more scalable.

An integrated F5 and Netscout solution eliminates the blind spots introduced by SSL/TLS encrypted content.

Versions Tested

This article assumes you have SSL Orchestrator configured with a Topology and Service Chain

F5 BIG-IP version 17.1

SSL Orchestrator version 11.0

Netscout vStream version 6.3.4

Netscout nGeniusONE version 6.3.4

Additional Help

If setting up SSL Orchestrator for the first time refer to the Deployment Guide available HERE

For information on SSL Certificate considerations and trust, click HERE

Demo Video

VMware ESX Configuration

Create the following 3 Port Groups:

Internal-north

Internal-south

Netscout-tap

Attach them to a vSwitch, Netscout-demo in this example:

Screen Shot 2023-07-14 at 8.25.45 AM.png

Configure the BIG-IP virtual settings as follows:

Screen Shot 2023-07-14 at 8.28.20 AM.png

NOTE:

VM Network is used for Management

Internal-north is used for connectivity to the North side of the network

Internal-south is used for connectivity to the South side of the network

Netscout-tap is used for decrypted connections from BIG-IP to Netscout vStream

Configure the Netscout vStream virtual settings as follows:

Screen Shot 2023-07-14 at 8.35.07 AM.png

NOTE:

VM Network is used for Management

Netscout-tap is used for decrypted connections from BIG-IP to Netscout vStream

Netscout Configuration

Use a web browser connect to the nGeniousONE management console.  Click Device Configuration.

Screen Shot 2023-07-14 at 8.39.54 AM.png

You should have at least one vStream device configured here.

Screen Shot 2023-07-14 at 8.45.35 AM.png

At this point Netscout nGeniusONE should be configured properly and ready to accept decrypted content from SSL Orchestrator.

BIG-IP SSL Orchestrator Configuration

The BIG-IP VLAN settings should look like the following:

Screen Shot 2023-07-14 at 10.40.21 AM.png

Internal-north is used for network connectivity from the BIG-IP to the North

Internal-south is used for network connectivity from the BIG-IP to the South

Netscout-tap is used for decrypted connections from BIG-IP to Netscout vStream

This article assumes you have SSL Orchestrator configured with a Topology and Service Chain.

Navigate to SSL Orchestrator > Configuration.

Screen Shot Dashboard 2023-06-20 at 9.00.47 AM.png

Create the Netscout Service

Under Services, click Add.

Screen Shot Services Add 2023-06-20 at 9.03.09 AM.png

In the Service Catalog select the TAP tab then double click on NETSCOUT TAP

Screen Shot 2023-07-14 at 10.50.01 AM.png

Give it a name, NETSCOUT in this example.  Enter the MAC Address of the vStream network adapter connected to the netscout-tap port group.

Screen Shot 2023-07-14 at 10.53.08 AM.png

NOTE: You can find the MAC Address in the vStream VM network settings.

Screen Shot 2023-07-14 at 10.57.16 AM.png

For the VLAN select Use Existing then netscout-tap

Enable Port Remap.  Set the Remap Port to 80

Click Save and Next.

Screen Shot 2023-07-14 at 11.00.34 AM.png

Click the name of the Service Chain.

Screen Shot Services Chain 2023-06-20 at 9.13.13 AM.png

Select the Netscout Service from the left and click the arrow to move it to the right.  Click Save.

Screen Shot 2023-07-14 at 11.04.04 AM.png

Click OK

Screen Shot Continue Save 2023-06-20 at 9.16.12 AM.png

Click Save & Next at the bottom.

Screen Shot Save Next 2023-06-20 at 9.17.06 AM.png

Click Deploy

Screen Shot Deploy 2023-06-20 at 9.17.58 AM.png

Click OK to the Success message.

Screen Shot 2023-07-14 at 11.08.21 AM.png

When done it should look like the following:

Screen Shot 2023-07-14 at 11.12.31 AM.png

Testing the Configuration

In this example there is a Windows client that connects through the SSL Orchestrator to a Windows server running the following web site:

https://192.168.0.5

Test this connection now and it should look like the following:

Screen Shot 2023-03-29 at 11.37.25 AM.png

We’ll use tcpdump on the BIG-IP to verify connectivity.

The capture from the internal-south vlan shows the encrypted HTTPS request

Screen Shot 2023-07-14 at 11.32.07 AM.png

The capture from the netscout-tap vlan shows plain text HTTP content being sent to Netscout for Inspection

Screen Shot 2023-07-14 at 11.41.20 AM.png

Netscout nGeniusONE Monitors

Check the Traffic Monitor to view statistics

Screen Shot 2023-07-14 at 2.24.47 PM.png

Zoom into the HTTP request that has been decrypted by SSL Orchestrator

Screen Shot 2023-07-17 at 8.46.14 AM.png

You can also see the server response in clear text

Screen Shot 2023-07-17 at 8.46.52 AM.png

Conclusion

This completes configuration of BIG-IP SSL Orchestrator with Netscout. At this point traffic that flows through SSL Orchestrator will be decrypted and sent to the Netscout Service and inspected.

Version history
Last update:
‎04-Aug-2023 07:58
Updated by: