[fw-wiz] Understanding Firewall and SSL Accelerator





Hi,
I am new to this list and I am trying to understand a typical scenario
In this scenario, F5 BigIP is used along with the hardware firewall to
offload SSL traffic from webservers. Now, my confusion is,

1. Who identifies if the incoming traffic is HTTP or HTTPS ? Hardware
firewall or the BigIP ?
2. Firewall forwards the HTTPS request to BigIP ? How does it know which
IP it needs to forward as the same IP will be used for both HTTP and
HTTPS .. ?
3. How does BigIP forwards the request to firewall ?
4. How does webserver sends back the response tp BigIP for encryption ?
5. How does BigIP knows which client to return back the request ?


Sundeep Sharma| Senior Associate, Technology | ¬ Sapient
DLF Cyber Greens, DLF City Phase III, Sector 25-A, Gurgaon, Haryana 122002, India
*Desk :+91.124.280.6476 | Fax: +91.124.280.8015 | Mobile : +91.9891482931


_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • [fw-wiz] RE: Arch questions
    ... The firewall won't be any more or less secure if you go either way. ... The BigIP provides a speed improvement by not requiring ... your web server to any of the crypto, and also gives you a LOT more ... You technically only need 1 SSL cert on the BigIP itself, ...
    (Firewall-Wizards)
  • RE: [fw-wiz] Understanding Firewall and SSL Accelerator
    ... I would recommend handing this with the firewall ... One possible reason not to do it my way is that you're also using the BigIP ... both HTTP and HTTPS traffic before sending it on to the web servers. ...
    (Firewall-Wizards)
  • Re: BigIP / ASP.NET Webservice Bad Request
    ... I made an attempt to put this application behind a BigIP box. ... > webserver and found that the real response sent from the webserver was ... invalid request. ... to install netmon.exe (this is a network sniffer from the ...
    (microsoft.public.inetserver.iis)
  • Re: BigIP / ASP.NET Webservice Bad Request
    ... > Egbert Nierop (MVP for IIS) wrote: ... > It says request line + headers. ... I suspect that the BigIP ... > sent regardless of the server response. ...
    (microsoft.public.inetserver.iis)
  • Re: BigIP / ASP.NET Webservice Bad Request
    ... It says request line + headers. ... I suspect that the BigIP ... One thing with the captured data though; it appears as the post data is ... sent regardless of the server response. ...
    (microsoft.public.inetserver.iis)