<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL-proxy list redirection in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ssl-proxy-list-redirection/m-p/515023#M9717</link>
    <description>&lt;P&gt;when I configure an ssl-proxy-list I end up with redirecting the un-encrypted connection to the CSS on a new port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;  ssl-server 1 &lt;/P&gt;&lt;P&gt;  ssl-server 1 rsakey my_key &lt;/P&gt;&lt;P&gt;  ssl-server 1 rsacert my_cert &lt;/P&gt;&lt;P&gt;  ssl-server 1 vip address 11.22.33.44 &lt;/P&gt;&lt;P&gt;  ssl-server 1 cipher rsa-with-rc4-128-md5 11.22.33.44 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it seems like if I have to have the un-encrypted port open to the internet in order to it to work, wich might be something I don't want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to have the CSS decrypt the HTTPS connection and then redirect it to a content wich isn't accessible to the internet ?&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2006 09:15:21 GMT</pubDate>
    <dc:creator>halldorhg</dc:creator>
    <dc:date>2006-07-27T09:15:21Z</dc:date>
    <item>
      <title>SSL-proxy list redirection</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-proxy-list-redirection/m-p/515023#M9717</link>
      <description>&lt;P&gt;when I configure an ssl-proxy-list I end up with redirecting the un-encrypted connection to the CSS on a new port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;  ssl-server 1 &lt;/P&gt;&lt;P&gt;  ssl-server 1 rsakey my_key &lt;/P&gt;&lt;P&gt;  ssl-server 1 rsacert my_cert &lt;/P&gt;&lt;P&gt;  ssl-server 1 vip address 11.22.33.44 &lt;/P&gt;&lt;P&gt;  ssl-server 1 cipher rsa-with-rc4-128-md5 11.22.33.44 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it seems like if I have to have the un-encrypted port open to the internet in order to it to work, wich might be something I don't want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to have the CSS decrypt the HTTPS connection and then redirect it to a content wich isn't accessible to the internet ?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2006 09:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-proxy-list-redirection/m-p/515023#M9717</guid>
      <dc:creator>halldorhg</dc:creator>
      <dc:date>2006-07-27T09:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-proxy list redirection</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-proxy-list-redirection/m-p/515024#M9718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can change the port 80 at the end of your cipher.&lt;/P&gt;&lt;P&gt;A lot of people use 81.&lt;/P&gt;&lt;P&gt;However, a user that would try port 81 could still access the un-encrypted content.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't want people accessing the clear text content, you should filter before it gets to the CSS with your firewall or an acl on your gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jul 2006 06:25:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-proxy-list-redirection/m-p/515024#M9718</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2006-07-28T06:25:14Z</dc:date>
    </item>
  </channel>
</rss>

