B-19
Cisco 11000 Series Secure Content Accelerator Configuration Guide
78-13124-06
Appendix B Deployment Examples
Use with the CSS
session-cache timeout 300
session-cache enable
no clientauth enable
clientauth verifydepth 1
clientauth error cert-other-error fail
clientauth error cert-not-provided fail
clientauth error cert-has-expired fail
clientauth error cert-not-yet-valid fail
clientauth error cert-has-invalid-ca fail
clientauth error cert-has-signature-failure fail
clientauth error cert-revoked fail
sharedcipher error failhtml
ephemeral error failhtml
no httpheader client-cert
no httpheader server-cert
no httpheader session
no httpheader pre-filter
httpheader prefix “SSL”
ephrsa
keepalive frequency 5
keepalive maxfailure 3
no keepalive enable
end
end
One-Armed Transparent Proxy
This deployment uses a single CSS for load balancing up to 15 Secure Content
Accelerator devices. The deployment combines the single CSS solution of the
proxy deployment with the transparency of the sandwich deployment.
The one-armed transparent proxy deployment is the most complex to configure,
but it provides a high degree of scalability and extended features, including IP
address accounting. Figure B-5 shows a typical deployment.