
Chapter 4: Configuring the High-Level Network
4-88
Table 4.17 lists the configurable SSL proxy options.
Creating an SSL Accelerator Proxy
When creating an SSL Accelerator proxy, you can enable the proxy to
handle either client-side SSL connections only, or both client-side and
server-side SSL connections. The following procedures describe how to
configure the SSL proxy for client-side connections only. To configure the
proxy for server-side connections, see Configuring SSL-to-Server, on page
4-90.
Options Description
SSL-to-Server
configuration
Causes the BIG-IP to re-encrypt decrypted requests before sending them to the server, as a
way to maintain server-side security.
Client-side
authentication
Allows you to configure the SSL proxy to either request, require, or ignore certificates presented
by a client.
Server-side
authentication
Allows you to configure certificate authentication between the SSL proxy and a content server.
This capability is part of the SSL-to-Server feature.
HTTP header
insertion
Allows you to configure an SSL proxy to insert various types of headers into HTTP requests.
For more information, see Inserting headers into HTTP requests.
Specification of
ciphers and
protocol versions
Allows you to configure an SSL proxy to require specific ciphers or protocol versions. For more
information, see Specifying SSL ciphers and protocol versions.
Configuration of
trusted CAs
Allows you to configure certificate chaining and verification, as well as to configure the proxy to
send to a client a list of CAs that the proxy trusts.
Rewriting of HTTP
redirection
Allows you to configure the proxy to convert HTTP redirects to HTTPS redirects.
SSL session cache
configuration
Allows you to configure the proxy to set a timeout value and a size for the SSL session cache.
SSL proxy failover
configuration
Allows you to configure the proxy to initiate a failover on a redundant BIG-IP in the event of a
fatal cryptographic hardware failure.
Shutdown
configuration
Allows you to configure the way in which the proxy manages clean and unclean shutdowns of
SSL connections.
Disabling of arp
requests
Allows you to disable the proxy address for ARP requests
.
lasthop pool
configuration
Allows you to add a last hop pool to an SSL proxy.
proxy deletion Allows you to delete an SSL proxy.
Table 4.17 Configuration options for the SSL Accelerator
Kommentare zu diesen Handbüchern