Ssl Full Proxy Configuration - One Ssl Module - Cisco 11503 - CSS Content Services Switch Configuration Manual

Content services switch ssl configuration guide
Hide thumbs Also See for 11503 - CSS Content Services Switch:
Table of Contents

Advertisement

Chapter 8
Examples of CSS SSL Configurations
SSL Full Proxy Configuration
OL-5655-01
content http-ssl-rule
vip address 192.28.4.4
protocol tcp
port 8080
url "/*"
add service serverDEF
add service serverJKL
advanced-balance arrowpoint-cookie
active
An SSL full proxy server is a proxy server that terminates the client's SSL
connections and initiates the back-end connection to the HTTP server using a
different source IP address than that of the client. This configuration does not
preserve the client's IP address for the back-end connection to the HTTP server.
This section provides an example configuration for an SSL full proxy between a
client, a CSS with a single SSL module, and three HTTP servers (ServerABC,
ServerDEF, and ServerGHI). A Layer 5 sticky content rule is used in the
configuration. For the CSS to implement a full proxy configuration with an SSL
module, the configuration includes a source group that is used to isolate the SSL
module traffic and to NAT its source address.
Figure 8-6
illustrates this full proxy configuration.
For purposes of illustration, the configuration example in
VIP address for the SSL content rule (ssl-rule) to be the same as the VIP address
for the HTTP content rule (http-rule). These two VIP addresses do not have to be
identical. Depending on the method that you choose to allow access to secure
content on your HTTP servers, you may require specification of a different VIP
address for the clear-text content rule to place it in nonroutable address space.
In this example, instead of specifying a VIP address of 192.168.5.5 for the
http-rule content rule, you could specify a VIP address of 10.1.1.5. The clear-text
http-rule will be unreachable from the Internet, which can offer you more
flexibility and granularity while allowing the CSS to be seamlessly integrated for
secure transactions.
One SSL Module
Cisco Content Services Switch SSL Configuration Guide
Figure 8-6
shows the
8-17

Advertisement

Table of Contents
loading

This manual is also suitable for:

11500 series

Table of Contents