F5 BIG-IP SSL Orchestrator with SWGaaS

F5 DevCentral CommunityAbout 3 min readJun 10, 2026Watch original
THE SUMMARYAI-generated

Key Concepts

  • SSL Orchestrator (SSLO): A platform that manages traffic flow and service chaining for security devices.
  • Secure Web Gateway (SWG): An F5 module that provides URL filtering, user authentication, and malicious content inspection.
  • Per-Request Policy (PRP): A granular policy framework that evaluates HTTP requests in real-time to determine access based on categories and security checks.
  • Service Chaining: The process of directing decrypted traffic through specific security services (like SWG) within the SSLO platform.
  • SSL Decryption/Interception: The process of decrypting traffic to inspect content, re-encrypting it, and presenting it to the client using a trusted certificate (e.g., f5labs.com).

1. Overview of F5 Secure Web Gateway (SWG) Integration

The F5 SSL Orchestrator now supports the integration of the Secure Web Gateway as a service. This allows administrators to enforce security policies—such as URL filtering and user authentication—directly within the SSLO service chain. By running SWG as a service, organizations can centralize traffic inspection and policy enforcement on a single platform.

2. Configuration and Provisioning

To implement SWG within the SSL Orchestrator, the following steps are required:

  • Provisioning: The SWG module must be enabled on the Big-IP system.
  • URL Filtering Configuration: Administrators define a "Corporate URL Filter" where specific categories (e.g., Shopping, Sports) are explicitly set to "Allow" or "Block."
  • Per-Request Policy (PRP) Setup:
    • The policy validates that the traffic is HTTP.
    • It performs a category lookup based on the HTTP URI.
    • It triggers Response Analytics to scan for malicious content.
    • The final decision (Allow/Deny) is determined by the intersection of the category lookup and the security scan results.

3. Orchestration via NSO (Network Services Orchestrator)

The integration simplifies deployment through the NSO interface:

  • Service Addition: Within the NSO topology, users select the F5 tab and choose "F5 Secure Web Gateway."
  • Access Profiles: Users must select the appropriate access profile. In environments with multiple profiles (e.g., separate authentication profiles), the system allows for the management of shared user access scopes.
  • Service Chaining: Once the profile and PRP are selected, the service is moved into the SSLO service chain, enabling it to process traffic dynamically.

4. Real-World Application and Testing

The demonstration highlights the effectiveness of the integration through a client-side test:

  • SSL Decryption Verification: When accessing a site like f5.com, the browser shows the certificate is verified by f5labs.com rather than the original CA. This confirms that the SSL Orchestrator is successfully intercepting and decrypting the traffic for inspection.
  • Policy Enforcement:
    • Blocked Content: Attempting to access "Yahoo Sports" or "Amazon" results in an immediate block page.
    • User Feedback: The block page provides the user with the specific category that triggered the block (e.g., "Sports") and a unique reference number for administrative tracking.

5. Logical Workflow Summary

  1. Traffic Interception: SSL Orchestrator decrypts incoming traffic.
  2. Policy Evaluation: The Per-Request Policy checks the URI against the Corporate URL Filter.
  3. Security Inspection: Response Analytics checks for malicious content.
  4. Enforcement: If the category is blocked or malicious content is detected, the request is denied; otherwise, it is allowed.
  5. Re-encryption: The traffic is re-encrypted and forwarded to the destination.

Conclusion

The integration of the F5 Secure Web Gateway into the SSL Orchestrator provides a streamlined, policy-driven approach to web security. By leveraging NSO for orchestration, administrators can easily manage complex service chains, ensure deep packet inspection through SSL decryption, and enforce granular access control based on URL categories and real-time security analytics. This setup reduces complexity while maintaining high security standards for user web traffic.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.