<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to terminate SSL encryption on ACE following IPS scan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039296#M79343</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This does not apply to your design. The VPN will be encr/decr on the edge ASA device. For inbound traffic (from the outside) it will be decrypted by the edge ASA, processed by the CSC, then by the second ASA+IPS and then it will reach the LAN host/server. In the opposite directon, it will be procesed by ASA+IPS, then ASA+CSC then encrypted by the ASA 'outside' interface and finally go out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Aug 2008 05:53:42 GMT</pubDate>
    <dc:creator>Farrukh Haroon</dc:creator>
    <dc:date>2008-08-07T05:53:42Z</dc:date>
    <item>
      <title>How to terminate SSL encryption on ACE following IPS scan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039287#M79334</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Query on SSL termination. Following is the logical path, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The encrypted traffic hits the router -&amp;gt; hits the ASA IPS -&amp;gt; and then hits the VIP for load balancing via ACE. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SSL encrypted traffic should terminate on the ACE load balancer. However, the IPS scan can only be performed on a decrypted traffic. &lt;/P&gt;&lt;P&gt;How can we re-encrypt the traffic to terminate on the load balancer. Or is it a bad idea due to performance issues ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:12:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039287#M79334</guid>
      <dc:creator>cisco_realm</dc:creator>
      <dc:date>2019-03-10T11:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to terminate SSL encryption on ACE following IPS scan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039288#M79335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SSL termination occurs when the ACE, acting as an SSL proxy server, terminates an SSL connection from a client and then establishes a TCP connection to an HTTP server. When the ACE terminates the SSL connection, it decrypts the ciphertext from the client and transmits the data as clear text to an HTTP server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2008 21:32:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039288#M79335</guid>
      <dc:creator>hadbou</dc:creator>
      <dc:date>2008-07-30T21:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to terminate SSL encryption on ACE following IPS scan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039289#M79336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok. But if the Cisco ASA IPS module is placed before the ACE, how will the SSL be handled. Will the ciphertext be decrypted for IPS checking and then re-encrypted for termination at the ACE. Is it possible and is it the right way to go about it ?  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Aug 2008 12:39:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039289#M79336</guid>
      <dc:creator>cisco_realm</dc:creator>
      <dc:date>2008-08-03T12:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to terminate SSL encryption on ACE following IPS scan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039290#M79337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No SSL decryption is not supported on the Cisco IPS. McAfee claim to support such a feature AFAIR (however still you need to load some keys on the IPS to make this happen, this is usually not possible for servers out of your control).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Aug 2008 01:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039290#M79337</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-04T01:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to terminate SSL encryption on ACE following IPS scan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039291#M79338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in other words it means that the traffic should be decrypted before Cisco IPS is hit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The relevant design is; the incoming traffic hits&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) ASA with CSC-SSM, then it hits&lt;/P&gt;&lt;P&gt;2) ASA with AIP (IPS), then it hits&lt;/P&gt;&lt;P&gt;3) Cisco ACE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, if the decryption should take place before IPS, then it can only be on Cisco ASA (CSC-SSM). Please confirm. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 07:24:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039291#M79338</guid>
      <dc:creator>cisco_realm</dc:creator>
      <dc:date>2008-08-06T07:24:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to terminate SSL encryption on ACE following IPS scan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039292#M79339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Even if there is no second ASA (with CSC), the first ASA (with IPS) can decrypt the trafic and send it to the IPS module installed on it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 07:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039292#M79339</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-06T07:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to terminate SSL encryption on ACE following IPS scan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039293#M79340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh, if I am not mistaken then the CSC module also requires decrypted traffic for virus checking. So in this design, the traffic will have to be decrypted at the internet edge device i.e Cisco ASA with CSC module. Right ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 08:44:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039293#M79340</guid>
      <dc:creator>cisco_realm</dc:creator>
      <dc:date>2008-08-06T08:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to terminate SSL encryption on ACE following IPS scan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039294#M79341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes your understanding is spot on. Both IPS/CSC need decrypted traffic to do anything meaningful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 09:19:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039294#M79341</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-06T09:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to terminate SSL encryption on ACE following IPS scan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039295#M79342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You had mentioned in earlier post that Cisco ASA IPS module doesn't have the ability to re-encrypt the trafffic. Is the same applicable to Cisco ASA CSC module as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 04:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039295#M79342</guid>
      <dc:creator>cisco_realm</dc:creator>
      <dc:date>2008-08-07T04:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to terminate SSL encryption on ACE following IPS scan</title>
      <link>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039296#M79343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This does not apply to your design. The VPN will be encr/decr on the edge ASA device. For inbound traffic (from the outside) it will be decrypted by the edge ASA, processed by the CSC, then by the second ASA+IPS and then it will reach the LAN host/server. In the opposite directon, it will be procesed by ASA+IPS, then ASA+CSC then encrypted by the ASA 'outside' interface and finally go out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Aug 2008 05:53:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-terminate-ssl-encryption-on-ace-following-ips-scan/m-p/1039296#M79343</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-07T05:53:42Z</dc:date>
    </item>
  </channel>
</rss>

