<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACE functionally question - SSL tunnelling / proxy on behalf of  in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-functionally-question-ssl-tunnelling-proxy-on-behalf-of-non/m-p/1985307#M37849</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes. The ACE SSL Configuration Guide shows how to do this in the "Configuring SSL Initiation" section, culminating in a worked example. The only gotcha is forgetting to specify the port 443 in the serverfarm - otherwise the ACE will send traffic to port 80 (the same destination port as the client request). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cathy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Jul 2012 16:30:59 GMT</pubDate>
    <dc:creator>ciscocsoc</dc:creator>
    <dc:date>2012-07-11T16:30:59Z</dc:date>
    <item>
      <title>ACE functionally question - SSL tunnelling / proxy on behalf of non SSL client</title>
      <link>https://community.cisco.com/t5/application-networking/ace-functionally-question-ssl-tunnelling-proxy-on-behalf-of-non/m-p/1985306#M37848</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can the ACE perform SSL tunnelling of web services(HTTP) traffic. Can ACE perform SSL tunnelling/proxy on behalf of a non SSL client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;Client (HTTP) ----&amp;gt;&amp;gt;&amp;gt; (HTTP)Cisco ACE(HTTPS) ------&amp;gt;&amp;gt;&amp;gt;&amp;gt;(HTTPS) Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "client" Server does not support SSL. &lt;/P&gt;&lt;P&gt;Can an ACE tunnel the web services traffic inside an SSL tunnel to a specific destination server on behalf of the client server (that does not support SSL)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any other Cisco products that could be used to perform this SSL tunnelling on behalf of a non SSL Client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2012 16:06:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-functionally-question-ssl-tunnelling-proxy-on-behalf-of-non/m-p/1985306#M37848</guid>
      <dc:creator>byron.momsen</dc:creator>
      <dc:date>2012-07-11T16:06:20Z</dc:date>
    </item>
    <item>
      <title>ACE functionally question - SSL tunnelling / proxy on behalf of</title>
      <link>https://community.cisco.com/t5/application-networking/ace-functionally-question-ssl-tunnelling-proxy-on-behalf-of-non/m-p/1985307#M37849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes. The ACE SSL Configuration Guide shows how to do this in the "Configuring SSL Initiation" section, culminating in a worked example. The only gotcha is forgetting to specify the port 443 in the serverfarm - otherwise the ACE will send traffic to port 80 (the same destination port as the client request). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cathy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2012 16:30:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-functionally-question-ssl-tunnelling-proxy-on-behalf-of-non/m-p/1985307#M37849</guid>
      <dc:creator>ciscocsoc</dc:creator>
      <dc:date>2012-07-11T16:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: ACE functionally question - SSL tunnelling / proxy on behalf</title>
      <link>https://community.cisco.com/t5/application-networking/ace-functionally-question-ssl-tunnelling-proxy-on-behalf-of-non/m-p/1985308#M37850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Byron, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, the ACE can do it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here you have some of the flavors of SSL with the ACE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG height="287" id="il_fi" src="http://docwiki.cisco.com/w/images/1/18/ACE_SSL_Configurations.jpg" style="padding-right: 8px; padding-top: 8px; padding-bottom: 8px;" width="386" /&gt;&lt;/P&gt;&lt;P&gt;Here you have a sample about it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type http CASE_PARAM&lt;/P&gt;&lt;P&gt;&amp;nbsp; case-insensitive&lt;/P&gt;&lt;P&gt;&amp;nbsp; persistence-rebalance&lt;/P&gt;&lt;P&gt;&amp;nbsp; set header-maxparse-length 65535&lt;/P&gt;&lt;P&gt;&amp;nbsp; set content-maxparse-length 65535&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all CLEAR_TEXT_VIP&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 172.20.120.19 tcp eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match JORGE-MULTIMATCH&lt;/P&gt;&lt;P&gt;&amp;nbsp; class CLEAR_TEXT_VIP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy POLICY_TO_ENCRYPT_TRAFFIC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options CASE_PARAM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match POLICY_TO_ENCRYPT_TRAFFIC&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm ENCRYPTED-SERVERFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy client SSL-PROXY-JORGE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl-proxy service SSL-PROXY-JORGE&lt;/P&gt;&lt;P&gt;&amp;nbsp; key TAC-key&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert TAC-cert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host ENCRYPTED-SERVERFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver JORGE-SERVER 443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here you have some additional details under the configuration guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA3_1_0/configuration/ssl/guide/initiate.html" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA3_1_0/configuration/ssl/guide/initiate.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here you have some additional samples:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://docwiki.cisco.com/wiki/Cisco_Application_Control_Engine_%28ACE%29_Configuration_Examples_--_SSL_Configuration_Examples" rel="nofollow"&gt;http://docwiki.cisco.com/wiki/Cisco_Application_Control_Engine_%28ACE%29_Configuration_Examples_--_SSL_Configuration_Examples&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps for you and fix your issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2012 22:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-functionally-question-ssl-tunnelling-proxy-on-behalf-of-non/m-p/1985308#M37850</guid>
      <dc:creator>Jorge Bejarano</dc:creator>
      <dc:date>2012-07-11T22:22:07Z</dc:date>
    </item>
  </channel>
</rss>

