Key Concepts
- Policy-Based Dynamic Egress Routing: A method to route outbound traffic based on specific criteria (e.g., protocol, VLAN).
- Pool: A logical group of backend servers or gateways to which traffic is forwarded.
- Traffic Policy: A set of rules that define how traffic is handled based on conditions (e.g., TCP, VLAN ID).
- Inspection Server Persistence: A mechanism ensuring that traffic from a specific client consistently reaches the same inspection device.
- Relaxed Protocol Compliance: A configuration setting (HTTP Transparent) that allows for less stringent protocol validation for external sites.
- SSL Orchestrator (SSLO): A solution for managing SSL/TLS traffic inspection and orchestration.
1. Configuring Policy-Based Dynamic Egress Routing
The process involves creating a destination pool and defining a traffic policy to govern egress flow.
- Step 1: Create a Pool: Navigate to "Local Traffic" and create a new pool. Assign a name (e.g., "egress two"), select a health monitor, and input the IP addresses of the destination egress points.
- Step 2: Create a Traffic Policy: Create a draft policy (e.g., "demo dynamic egress").
- Step 3: Define Rules: Within the policy, create a rule (e.g., "egress rule one").
- Conditions: Set criteria such as protocol (TCP) and VLAN ID (e.g., 104).
- Event: Set the trigger time to "client accepted."
- Action: Select "forward traffic to pool" and choose the pool created in Step 1.
- Step 4: Publish and Assign: Save and publish the policy. Navigate to the Virtual Server used by SSL Orchestrator, go to the "Resources" section, and add the newly created policy to the "Enabled" list.
2. Configuring Inspection Server Persistence
Persistence ensures that a client’s session remains pinned to a specific inspection device, which is critical for stateful inspection.
- Process: Navigate to SSL Orchestrator > Services > Create.
- Configuration: When creating a service, locate the "Persistence" field.
- Options:
- L2 Services: Offers specific default persistence profiles.
- Inline HTTP Services: Offers "Universal" persistence options.
- Action: Select the desired persistence profile from the dropdown menu instead of leaving it as "None."
3. Relaxed Protocol Compliance
SSL Orchestrator allows for "relaxed" protocol compliance, which is useful when dealing with external sites that may not strictly adhere to standard HTTP protocols.
- Topology Level: In the interception rule for a back topology, the default L7 profile can be changed to "HTTP Transparent." This setting applies to all connections egressing that topology.
- Service Level: This can also be configured on a per-service basis. When configuring an HTTP service, change the outgoing HTTP profile from the standard "HTTP" option to "HTTP Transparent."
- Deployment: After modifying these settings, the changes must be saved and deployed to take effect.
Synthesis and Conclusion
The video outlines three advanced configuration workflows within the SSL Orchestrator environment.
- Dynamic Egress Routing provides granular control over outbound traffic paths based on network metadata (VLANs/Protocols).
- Inspection Server Persistence maintains session integrity across inspection devices, ensuring consistent security processing.
- Relaxed Protocol Compliance offers flexibility for modern web traffic, allowing administrators to bypass strict protocol enforcement via the "HTTP Transparent" profile when necessary.
These configurations collectively enhance the flexibility and reliability of traffic management within an SSL Orchestrator deployment.
AI summaries can miss context or contain errors. Check important details against the original video.