Forum Discussion

a_basharat_2591's avatar
a_basharat_2591
Icon for Nimbostratus rankNimbostratus
Nov 27, 2017

Bypass VS Interception on SSL Forward Proxy

Hi,

 

I am using APM+SWG to configure the F5 as Forward Proxy, using the iApp for setting up Secure web Gateway (SWG).

 

One of the option on it is: Select whether SSL traffic should be intercepted or bypassed by default

 

Bypass means that the client doesn't terminate the SSL connection on the F5, but it is bypassed by the F5 to be terminated on the Server?

 

Because Bypassing traffic I am NOT getting any Certificate Warning when accessing HTTPS websites, but when I switch it to 'Intercept' on the F5, I get Warnings on all the HTTPS Websites as I don't have CA signed certificates installed.

 

Thanks

 

1 Reply

  • Yes, bypass will not intercept SSL traffic. The client that is using the forward proxy will receive the official (authentic) certificate of the server it is connecting to. Bypass will prevent the BIG-IP to do HTTPS inspection for that connection.