Forum Discussion

Paolo's avatar
Paolo
Icon for Nimbostratus rankNimbostratus
May 27, 2019

BIG-IP SWG non standard ports

Good morning,

 

It is possible that the BIG-IP configured as an explicit proxy, in addition to using ports 80 and 443, use other non-standard ports for http and https traffic.

 

Is there any recommendation?

 

We made the configuration with the iAPP of F5.

 

Thank you!

1 Reply

  • When using the iApp I guess your options are limited. However, when building the explicit forward proxy manual, you can configure additional virtual servers that handle http or https on other non-standards ports.

     

    The explict forward proxy solution from F5 is build by using three virtual servers:

     

    1. Main VS that listens on port 8080 or 3128 and handles plain http traffic.
    2. Second VS that listens on port 443 and that handles https traffic.
    3. Reject VS that rejects all traffic on other ports (non-standard ports).

     

    To handle additional non-standard ports you can add virtual servers to this configuration. These virtual servers should listen on the same tunnel interface that are being used for the HTTPS and Reject VS.

     

    For more information on how to build the explicit forward proxy without an iApp see:

     

    https://techdocs.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-secure-web-gateway-13-1-0/2.html#guid-83fd235f-507a-4754-8640-f3cf629f5e7c