networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 6 posts ] 
Author Message
PostPosted: Tue Jul 17, 2012 2:48 pm 
Offline
Junior Member
Junior Member

Joined: Wed Nov 11, 2009 1:22 pm
Posts: 93
Certs: CCNA, A+, Network+, MCDST
When an ACE is configured in one-arm mode and only L3/L4 load balancing is enabled for a web site, is SSL termination on the ACE required? I'm trying to wrap my head around how the client's traffic will be encrypted if the ACE does NOT terminate SSL, since one arm mode creates two connections - one to the client and one to the rserver.


Top
 Profile  
 
PostPosted: Tue Jul 17, 2012 2:54 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Jan 17, 2005 11:01 pm
Posts: 5148
Location: Canada eh
Certs: 350-001, CCNP, CXFF, ITILv3F
There's a few ways you can do it. You can go without SSL termination, you can have the ACE terminate the SSL connection and pass on unencrypted, or you can have the ACE terminate SSL, then in turn use SSL to connect to the server.

It's really up to you.

_________________
blog.brokennetwork.ca


Top
 Profile  
 
PostPosted: Tue Jul 17, 2012 4:23 pm 
Offline
Junior Member
Junior Member

Joined: Wed Nov 11, 2009 1:22 pm
Posts: 93
Certs: CCNA, A+, Network+, MCDST
I'm familiar with the various SSL options (termination, backend, and end-to-end), but I wasn't sure if either of the 3 were a requirement when load balancing SSL traffic. It doesn't sound like they are.


Top
 Profile  
 
PostPosted: Tue Jul 17, 2012 4:45 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Jan 17, 2005 11:01 pm
Posts: 5148
Location: Canada eh
Certs: 350-001, CCNP, CXFF, ITILv3F
Nope, none are required.

Mobile Post

_________________
blog.brokennetwork.ca


Top
 Profile  
 
PostPosted: Tue Jul 17, 2012 6:29 pm 
Online
Post Whore
Post Whore
User avatar

Joined: Fri Nov 13, 2009 5:15 pm
Posts: 1957
Location: Pittsburgh
Certs: CCIE R&S,CCIP,JNCIA,VCP510
jdsilva wrote:
There's a few ways you can do it. You can go without SSL termination, you can have the ACE terminate the SSL connection and pass on unencrypted, or you can have the ACE terminate SSL, then in turn use SSL to connect to the server.

It's really up to you.



I would do this and offload the ssl unencrypted back to the servers/reals you are load balancing to. Its always easiest to apply the cert on the Ace.

_________________
"I will prepare and some day my chance will come." - Abraham Lincoln
http://danielhertzberg.wordpress.com - I blog about networks!


Top
 Profile  
 
PostPosted: Wed Jul 18, 2012 7:48 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8303
Location: Frederick MD
Certs: Instanity
if you have monitoring requirements, you should terminate the SSL on the firewall, then send it on to the server unencrypted through the trusted network, so the traffic can be monitored. monitoring SSL encrypted traffic is difficult.

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 8 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group