Working with Clusters and Match Rules
Server Side Encryption
Note
- Server Side Encryption is not supported on GX Series Equalizers.
In a potentially dangerous scenario, you may be load balancing traffic and forwarding it to back-
end servers along untrusted paths. Vital credit card and personally identifying information could
be vulnerable during its back-end transit to clients unless you-encrypt it. Server Side Encryption
(SSE) provides you with the ability to configure a cluster and/or match rule so that traffic between
Equalizer and back end servers is encrypted using SSL/TLS, eliminating the untrusted paths.
A client’s HTTPS request is encrypted along its path from the client to Equalizer. Equalizer
terminates the SSL/TLS connection with the client, decrypts the client request using a certificate
and key and then forwards unencrypted HTTP traffic to the servers. When the server replies, the
server connects with Equalizer via clear text HTTP. Equalizer, then encrypts the response and
forwards it via HTTPS back to the client. Using SSE, the vulnerable path between your appliance
and servers can be encrypted by enabling cluster options.
With Equalizer, Match Rules extend the Layer 7 load balancing capabilities of HTTP and HTTPS
clusters by allowing you to define a set of logical conditions which, when met by the contents of
the request, trigger the load balancing behavior specified in the match rule.You have the option of
utilizing this intelligence as you have the capability of encrypting packets specifically identified by
the match rule definitions.
Equalizer provides configuration options, whereby you could encrypt all traffic between the
servers and your appliance or content-specific traffic, based on a match rule.The table below
explains possible Cluster/Match Rule encryption scenarios:
Cluster/Match Rule Encryption Enabled
Usage
Cluster Enabled/Match Rule Enabled
Used to encrypt all packet transfers between Equalizer and all of
your servers.
Cluster Enabled/Match Rule Disabled
Used to encrypt all packet transfers from Equalizer, regardless of
match rule definitions.
Cluster Disabled/Match Rule Enabled
Used to encrypt only those packets specified by the enabled match
rule definition.
358
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......