Cisco Explorer 4700 Installationsanleitung Seite 328

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 648
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 327
9-2
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 9 Configuring SSL
SSL Overview
SSL Overview
SSL is an application-level protocol that provides encryption technology for the Internet, ensuring
secure transactions such as the transmission of credit card numbers for e-commerce Web sites. SSL
initiation occurs when the ACE appliance acts as a client and initiates the SSL session between it and
the SSL server. SSL termination occurs when the ACE, acting as an SSL server, terminates an SSL
connection from a client and then establishes a TCP connection to an HTTP server.
SSL provides the secure transaction of data between a client and a server through a combination of
privacy, authentication, and data integrity. SSL relies upon certificates and private-public key exchange
pairs for this level of security.
Figure 9-1 shows the following network connections in which the ACE terminates the SSL connection
with the client:
Client to ACE—SSL connection between a client and the ACE acting as an SSL proxy server
ACE to Server—TCP connection between the ACE and the HTTP server
Figure 9-1 SSL Termination with Client
The ACE uses parameter maps, SSL proxy services, and class maps to build the policy maps that
determine the flow of information between the client, the ACE, and the server. SSL termination is a
Layer 3 and Layer 4 application because it is based on the destination IP addresses of the inbound traffic
flow from the client. For this type of application, you create a Layer 3 and Layer 4 policy map that the
ACE applies to the inbound traffic.
If you have a need to delete any of the SSL objects (auth groups, chain groups, parameter maps, keys,
CRLs, or certificates), you must remove the dependency from within the proxy service first before
removing the SSL object.
Before configuring the ACE for SSL, see SSL Configuration Prerequisites, page 9-3.
Client
Front-end
Back-end
Server
Ciphertext Clear Text
SSL Termination
(ACE as Server)
153357
Seitenansicht 327
1 2 ... 323 324 325 326 327 328 329 330 331 332 333 ... 647 648

Kommentare zu diesen Handbüchern

Keine Kommentare