![F5 Herculon SSL Orchestrator Скачать руководство пользователя страница 17](http://html.mh-extra.com/html/f5/herculon-ssl-orchestrator/herculon-ssl-orchestrator_setup_535213017.webp)
5.
From the
Which is the SSL Forward Proxy CA private key?
list, select the corresponding private
key.
You import the CA certificate and private key while configuring the Setup Wizard. If you did not use
the Setup Wizard, you must import a CA certificate before you can use this functionality.
6.
In the
What is the private-key passphrase (if any)?
field, type the private-key passphrase.
If the key does not have a passphrase, leave the field empty.
7.
From the Ingress Device Configuration area, for the
Which VLAN(s) will bring client traffic to the
transparent proxy?
setting, select one or more VLANs where transparent-proxy ingress traffic will
arrive.
8.
From the
How should a server TLS handshake failure be handled?
list, select whether you want
the connection to fail or bypass the connection.
9.
From the
DNS query resolution
list, select whether to permit the system to send DNS queries
directly out to the Internet, or specify one or more local forwarding nameservers to process all DNS
queries from Herculon SSL Orchestrator.
• If you select
Send DNS queries directly to nameservers across the internet
, proceed to step 10.
• If you select
Send DNS queries to forwarding nameservers on the local network
, proceed to
step 11.
10.
From the
Do you want to configure local/private DNS zones?
list, select whether you do, or do not,
want to configure local or private DNS zones.
• If you select
No, do not configure any local/private DNS zones
, proceed to step 13.
• If you select
Yes, configure local/private DNS zones
, proceed to step 12.
11.
In the
Which local forwarding nameserver(s) will resolve DNS queries from this solution?
field,
type the IP address of local nameservers that will resolve all DNS queries from this implementation
and click
Add
. Once you have added the necessary nameserver IP addresses, proceed to step 13.
12.
In the
List local/private Forward Zones
setting, click
Add
and type the IP address of one or more
nameservers.
13.
From the
Do you want to use DNSSEC to validate DNS information?
list, select whether you do,
or do not, want to use DNSSEC to validate the DNS information.
14.
In the Egress Device Configuration area, from the
Do you want to SNAT client IP addresses?
list,
select whether you do, or do not, want to define SNAT addresses.
• If you select
No, pass client addresses unaltered
, proceed to step 17.
• If you select
Yes, SNAT (replace) client addresses
, proceed to step 15.
15.
From the
Do you want to use a SNAT Pool?
list, select whether you want to use a SNAT pool or
SNAT auto map to translate addresses.
• If you select
Yes, define SNAT Pool addresses for good performance
, proceed to step 16.
• If you select
No, use SNAT Auto Map (not recommended)
, proceed to step 17.
16.
Options to provide SNAT addresses will vary, whether you selected
Support IPv4 only
,
Support
IPv6 only
, or
Both IPv4 and IPv6
. Enter at least as many IP host addresses as the number of TMM
instances on the ingress device. Type address must be uniquely assigned and routed to the ingress
device. It is best to assign addresses which are adjacent and grouped under a CIDR mask, for
example, 203.0.113.8 up through 203.0.113.15 which fill 203.0.113.8/29.
• In the
IPv4 SNAT addresses
field, type the IPv4 SNAT address.
• In the
IPv6 SNAT addresses
field, type the IPv6 SNAT address.
• In both the
IPv4 SNAT addresses
and
IPv6 SNAT addresses
fields, type both the IPv4 and IPv6
SNAT addresses.
17.
From the
Should traffic go to the Internet via specific gateways?
list, select whether or not you
want the system to let all SSL traffic use the default route, or if you want to specify Internet gateways
(routers). If you chose to use specific gateways, you can also define the ratio of traffic sent to each
device in the next step.
F5 Herculon SSL Orchestrator: Setup
17
Содержание Herculon SSL Orchestrator
Страница 1: ...F5 Herculon SSL Orchestrator Setup Version 13 1 3 0 ...
Страница 2: ......
Страница 6: ...What is F5 Herculon SSL Orchestrator 6 ...
Страница 26: ...Setting Up a Basic Configuration 26 ...
Страница 38: ...Importing and Exporting Configurations for Deployment 38 ...
Страница 54: ...Using Herculon SSL Orchestrator Analytics 54 ...