Chapter 8 Examples of CSS SSL Configurations
8-18
Cisco Content Services Switch SSL Configuration Guide
OL-5655-01
Figure 8-6 Full Proxy Configuration Using a Single SSL Module
!*************************** GLOBAL ***************************
logging commands enable
ssl associate dsakey dsakey dsakey.pem
ssl associate dhparams dhparams dhparams.pem
ssl associate rsakey rsakey rsakey.pem
ssl associate cert rsacert rsacert.pem
ftp-record ssl_record 161.44.174.127 anonymous des-password
deye2gtcld1b6feeeebabfcfagyezc5f /
78268
Client A
Client IP address
172.16.6.58
Source = 172.16.6.58
Destination = 192.168.5.5
Layer 5 http-rule
Source group
ssl_module_proxy
translates IP 172.16.6.58
to VIP 192.168.7.200
Layer 5 ssl-rule
SSL
Acceleration
Module 1
VIP = 192.168.5.5
CSS 11506
Internet
ServerABC
192.168.7.1
ServerDEF
192.168.7.2
ServerGHI
192.168.7.3
Source = 192.168.7.200
Destination = 192.168.7.1
Ethernet
connection