Setting Up a Basic Configuration
Overview: Setting up a basic configuration
This section contains general information that the system needs before you can configure services and
service chains. The F5
®
Herculon
™
SSL Orchestrator
™
configuration utility will assist you with
configuring logging settings, setting up ingress and egress devices as one system or separate systems, and
configuring the system for transparent proxy and explicit proxy.
Configuring general properties
You must provide general information that the system needs so that you can then set up ingress and
egress devices, create services and service chains, and create classifier rules using the Herculon SSL
Orchestrator configuration utility.
Note: By default, during the Herculon SSL Orchestrator deployment process, the system database value
for Traffic Management Microkernel (TMM) fast forward is automatically disabled (set to “false”). To
ensure your Herculon SSL Orchestrator deployment works properly, make sure the system database value
for TMM fast forward remains disabled throughout the deployment. If you are not using Herculon SSL
Orchestrator and need the system database value for TMM fast forward enabled, it must be manually
changed.
1.
On the Main tab, click
SSL Orchestrator
>
Configuration
.
The General Properties screen opens.
2.
For the
Application Service Name
field,
ssloApp
is the default name for this configuration.
3.
From the
Do you want to setup separate ingress and egress devices with a cleartext zone between
them?
list, select one of the options:
• If the same BIG-IP system receives both ingress and egress traffic on different networks, use
No,
use one BIG-IP device for ingress and egress
.
• If you are configuring separate devices for ingress and egress traffic, use
Yes, configure separate
ingress and egress BIG-IP devices
.
4.
From the
Which IP address families do you want to support?
list, select whether you want this
configuration to
Support IPv4 only
,
Support IPv6 only
, or
Both IPv4 and IPv6
.
If you do not choose to support both address families, you must configure IP addresses in the family
you select for all IP address fields in this application. If you choose
Both IPv4 and IPv6
, you can
send intercepted IPv6 traffic through an IPv4 Layer 3 service device.
5.
From the
Which proxy schemes do you want to implement?
list, select whether the system operates
in transparent proxy mode, explicit proxy mode, or both.
• Use
Implement transparent proxy only
for the system to operate in transparent proxy mode.
The transparent proxy scheme can intercept all types of TLS and TCP traffic. It also processes
UDP traffic and forwards all other types of traffic. The transparent proxy requires no client
configuration modifications.
• Use
Implement both transparent and explicit proxies
for the system to operate in explicit and
transparent proxy modes simultaneously.
• Use
Implement explicit proxy only
for the system to operate in explicit proxy mode. The explicit
proxy scheme supports only HTTP(S) per RFC2616. If you choose to configure an explicit proxy,
assign a specific IP address and TCP port where the HTTP explicit-proxy clients connect.
Содержание Herculon SSL Orchestrator
Страница 1: ...F5 Herculon SSL Orchestrator Setup Version 13 1 3 0 ...
Страница 2: ......
Страница 6: ...What is F5 Herculon SSL Orchestrator 6 ...
Страница 26: ...Setting Up a Basic Configuration 26 ...
Страница 38: ...Importing and Exporting Configurations for Deployment 38 ...
Страница 54: ...Using Herculon SSL Orchestrator Analytics 54 ...