As shown in Figure-1, the device acts as the security gateway of an enterprise. The device cannot inspect SSL-encrypted packets (such as HTTPS packets), masking the security threats inside of the packets. To improve the internal network security, configure SSL decryption on the device to decrypt HTTPS packets for IPS inspection.
This configuration example was created and verified on R9900P2705 of the F5000-AI-55-G device.
When configuring SSL decryption, make sure the security policies allow the source and destination security zones to intercommunicate with the
SSL decryption supports decrypting HTTPS, SMTPS, IMAPS, and POP3S protocol packets.
Assign IP addresses to interfaces:
# On the top navigation bar, click
# From the navigation pane, select
# Click the
# In the dialog box that opens, configure the interface:
Select the
On the
Use the default settings for other parameters.
Click
# Add GE 1/0/2 to the
Configure settings for routing:
This example configures a static route to reach the Web server, and the next hop in the route is 20.1.1.2.
# On the top navigation bar, click
# From the navigation pane, select
# On the
# In the dialog box that opens, configure a static IPv4 route to reach the Web server:
Enter destination IP address
Enter mask length
Enter next hop address
Use the default settings for other parameters.
Click
Import the trusted SSL decryption certificate:
# On the top navigation bar, click
# From the navigation pane, select
# Click
# In the dialog box that opens, configure the following settings, as shown in Figure-2:
Select file
Enter the password of the file.
Set the certificate type to
# Click
Figure-2 Importing the trusted SSL decryption certificate
# Import the untrusted SSL decryption certificate in the same way you import the trusted SSL decryption certificate, as shown in Figure-3.
Figure-3 Importing the untrusted SSL decryption certificate
# On the top navigation bar, click
# From the navigation pane, select Application Proxy > Proxy Policy.
# Click
# In the dialog box that opens, configure a proxy policy:
Enter policy name
Select source security zones
Select destination security zones
Select service
Select action
Enable the policy.
Select
# Click
Figure-4 Creating a proxy policy
Configure IPS. For more information, see "IPS configuration examples."
Configure security policies:
# On the top navigation bar, click
# From the navigation pane, select Security Policies > Security Policies.
# Click Create, and then click
# Configure security policy
Enter policy name
Select type
Select source zone
Select destination zone
Select source IPv4 address
Select action
Select IPS profile
Use the default settings for other parameters.
Click
# Configure security policy
Enter policy name
Select type
Select source zone
Select destination zone
Select source IPv4 addresses
Select action
Select IPS profile
Use the default settings for other parameters.
Click
# Create security policy
Enter policy name
Select type
Select source zones
Select destination zones
Select action
Use the default settings for other parameters.
Click
# Create security policy
Enter policy name
Select type
Select source zones
Select destination zones
Select action
Use the default settings for other parameters.
Click
Verify that the device can perform SSL decryption on HTTPS packets, and then perform IPS inspection on the encrypted packets.