on 06-Jul-2016 05:42
You’ve been having trouble sleeping because of the SSL visibility problem with all the fancy security tools that don’t do decryption. Put down that ambien, because this Lightboard Lesson solves it. In episode, David Holmes diagrams the Right Way (tm) to decrypt and orchestrate outbound SSL traffic, improving SSL visibility, decreasing failures and improving network performance.
Great vid. Very digestible way of explaining it. Is there a with paper on this kind of set up? Or could you recommend reading material?
No problem at all. In fact, mystery answer is probably more fun than actual answer...so well played.
Great discussion on outbound SSL visibility. You forgot one important option; forwarding of traffic to a cloud-based filter that does everything the devices you mentioned does, in a single pass, and decrypts SSL once to do it. F5 LTM can simply build a GRE tunnel to that cloud service, and without the cost, complexity, and performance hit of distributing across multiple security appliances, or the addition of the SWG module, you have a.) SSL Visibility (even for DLP), b.) Resiliency of the cloud, and c.) Scalability of a cloud security platform that can grow in SSL performance for a reasonable recurring cost, much like you pay on all those security devices sitting in your data center that you backhaul all the traffic to in order to achieve this centralized processing of outbound SSL traffic. Nothing like combining the leader in inbound traffic management and security, with the leader in outbound traffic security in the cloud.
So it is 1 month later. Post Agility. Any update on the licensing information discussed above?
From my knowledge you will need the SSL forward proxy license, which is not included in the SWG license as far as i know. You can integrate SWG into the solution, but this is an option. The SSLi solution can also be run without SWG.