03-09-2006 03:40 AM
Is there any way to filter the initial client headers on a css11506 ssl module ?? (software version 8.1)
This is one of the default options on the "old" SCA11000 appliances.
03-14-2006 09:40 PM
Jaap,
In what way do you wish to filter the headers? You can use header field groups to load balance based on most headers that clients can send. When using an SSL module, you can also insert SSL specific headers into requests and responses.
Peter
06-12-2006 10:36 AM
Peter,
I thought that SSL filtering on anything above layer 4 was impossible for SSL because the payload is encrypted? Or are you refering to a HTTPS to HTTP redirect, with filters on the cleartext side of the conversation?
Thanks,
Douglas
06-12-2006 11:28 PM
Douglas, with an SSL module, the CSS can decrypt HTTPS traffic and see the cleartext HTTP traffic.
We can then apply any rules to the header.
I think in this case, the question refered to some data injected in the http header by the CSS and filter what data from the client certificate should be dropped or inserted.
We currently do not have this option on the CSS.
Gilles.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide