F5 BIGIP LTM原厂培训资料-1.ppt

  1. 1、本文档共133页,可阅读全部内容。
  2. 2、有哪些信誉好的足球投注网站(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
  3. 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载
  4. 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
F5 BIGIP LTM原厂培训资料-1

What is FIPS? FIPS 140-2 standard : “Security Requirements for Cryptographic Modules”. Standard SSL Server Keys? Can’t login to Servers, can’t get at keys. Isn’t Standard SSL good enough? Want keys in tamper-proof hardware. Who needs FIPS-140? Companies regulated by U.S. government Configuring FIPS Epoxied card Switch (MOI) Card Reader Change Key Note – old picture Generate Certificate Create SSL Profile Point VS to Profile SSL Termination Labs Client SSL : Generate Certificate Custom Client SSL profile vs_ssl 10.10.X.102:443 using Client SSL profile Test: Connect :443 to :80 web? Server SSL (Optional): Custom Server SSL profile vs_ssl using both Client and Server SSL profiles Test again: Internet 10.10.X.102:443 80 7 Course Outline Installation Load Balancing Health Monitors Profiles Persistence Processing SSL Traffic Lab Project NATs and SNATs iRules Redundant Pair High Availability Maintaining BIG-IP LTM Day 1 Day 2 Let’s look at insert mode cookie persistence in more detail: Client connects the first time: the web browser has yet to receive a cookie for this site. BIG-IP detects that no cookie is present, and forwards the connection to the most appropriate available node. The node issues its http reply to the client. BIG-IP inserts a cookie with the appropriate expiration value and specific node information. Client connects back a second time. This time the web browser inserts the cookie in its http request. BIG-IP reads the cookie, and forwards the connection to the specified server The node issues its http reply to the client. BIG-IP updates the expiration value in the cookie. The advantage of insert mode cookie persistence is that the web servers remain untouched. The drawback is that the BIG-IP controller has an increased workload. Note that the BIG-IP controller is unable to forward the incoming connection to the appropriate node until it receives the cookie. As such, it needs to perform the initial TCP handshake with the connecting client.

文档评论(0)

zhuwenmeijiale + 关注
实名认证
内容提供者

该用户很懒,什么也没介绍

版权声明书
用户编号:7065136142000003

1亿VIP精品文档

相关文档