
Introduction
BIG-IP® Reference Guide Intro - 7
SSL Accelerator proxy enhancements
This release includes several important enhancements to the SSL
Accelerator proxy. For example, you can now configure options such as
specifying ways for an SSL proxy to manage client certificates, inserting
headers into HTTP requests, specifying ciphers and protocol versions, and
configuring SSL session cache size and timeout values.
This release also supports the SSL-to-Server option, which allows you to
re-encrypt traffic after it has been decrypted by the BIG-IP. Previously
available on the IP Application Switch only, this feature is now available on
the BIG-IP Controller platform also. Moreover, this feature has been
enhanced in this release to further ensure the security of SSL connections
between the proxy and the server. For a complete description of all new SSL
Accelerator proxy options, see the Proxies section in Chapter 4, Configuring
the High-Level Network.
Support for the nCipher FIPS 140-1 level 3 certified SSL cryptographic
module
For BIG-IP Controller platforms, option is available to install a
FIPS 140-1-certified cryptographic network module. The BIG-IP FIPS
hardware option is specifically designed for processing SSL traffic within
environments that require FIPS 140-1 Level 3 compliant solutions. It comes
with the FIPS 140-1 level 3 certified PCI based encryption processing
module, attached smart card reader, and 5 smart cards. This product can be
installed in any BIG-IP Controller platform (D35) that has BIG-IP software
version 4.2 and is authorized by your vendor. For more information, see
Configuring FIPS 140 Security World on the BIG-IP in the Documentation
section of the Software and Documentation CD.
Enhanced support for Secure Network Address Translations (SNATs)
In previous releases, BIG-IP allowed you to automatically map VLANs to
translation IP addresses during SNAT creation. In this release, you can now
use this automapping feature not only for VLANs, but for one or more
individual IP addresses. For more information, see the Address Translation:
NATs, SNATs, and IP Forwarding section in Chapter 4, Configuring the
High-Level Network.
Enhanced interface statistics
This release features enhanced statistics for BIG-IP interfaces. The
following state information and statistics are now available: MTU, Speed,
MAC address, packets in, errors in, packets out, errors out, collisions,
dropped packets, bits in, bits out. Previously available on the IP Application
Switch, this feature is new for the BIG-IP Controller platform. For more
information, see Chapter 11, Monitoring and Administration.
Komentarze do niniejszej Instrukcji