|
Table Of Contents
Assigning Policies to Proxy Services
Viewing HTTP Header Insertion Policy
Adding HTTP Header Insertion Policy
Editing HTTP Header Insertion Policy
Deleting HTTP Header Insertion Policy
Managing Policies
The CVDM-SSLSM supports defining policies for Proxy Services. The policy templates help the Administrator customize the attributes associated with SSL and TCP stack to suit the needs.
The following policies are supported by the SSLSM:
• HTTP Header Insertion Policy
Policies are grouped by their type and are displayed as a tree node in the object selector. All configured policies of a type are listed as child nodes under the policy node.
Figure 8-1 Policies Page
TCP Policy
The TCP commands for the SSL Services Module apply either globally or to a particular proxy server.
The TCP policy template allows you to define parameters associated with the TCP stack.
Viewing TCP Policies
To view the TCP Polices:
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select TCP Policy from the object selector. The policy information appears on the page.
The following fields appear:
TCP Policies
Fields DescriptionPolicy Name
Name of the TCP Policy
Number of Proxy Services (Use Count)
Number of proxy services using the TCP Policy.
Select a policy, then click Assign to Proxy Services to assign a policy to the proxy services.
Click Add to add a new TCP policy. The Add TCP Policy dialog box appears.
Select a policy, then click Edit to edit a TCP policy. The Edit TCP Policy dialog box appears.
Select a policy, then click Delete to delete the policy.
Step 3 Select a policy from the TCP Policy table, then click Policy Tab to view the policy details or click Associated Proxy Services tab to view the proxy services associated with the policies.
TCP Policy Details
Assigning Policies to Proxy Services
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select a Policy from the object selector. The policy information appears on the page.
Step 3 Select a policy from the Policies table, then click Assign to Proxy Services.
The Assign Policy to Proxy Services dialog box appears with the following details:
Figure 8-2 Assigning Policies to Proxy Service
Step 4 Select a Proxy Service Name, then click Add >> to add the policy to the selected service.
You can remove the a proxy service from the list. Select a service from the list, then click << Remove.
You can clear all the services selected for assigning to a policy. Select a service from the list, then click Clear All.
Step 5 Click OK to complete the task.
Adding TCP Policy
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select TCP Policy from the object selector. The policy information appears on the page.
Step 3 Click Add. The Add TCP Policy dialog box appears.
Step 4 Click OK to add the new TCP Policy.
Editing TCP Policy
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select TCP Policy from the object selector. The policy information appears on the page.
Step 3 Click Edit. The Add TCP Policy dialog box appears.
Step 4 Click OK to save the new configuration for the TCP policy.
Deleting TCP Policy
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select TCP Policy from the object selector. The policy information appears on the page.
Step 3 Select a Policy from the list, then click Delete.
SSL Policy
The SSL policy option allows you to define parameters associated with the SSL stack.
If you do not associate an SSL policy with a particular proxy server, the proxy server enables all the supported cipher suites and protocol versions by default.
Viewing SSL Policy
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select SSL Policy from the object selector. The policy information appears on the page.
Field Description SSL PoliciesPolicy Name
The name of the SSL policy.
Number of Proxy Services (Use Count)
Number of proxy services using the SSL Policy.
Select a policy from the SSL Policies table, then Click Policy Tab to view the policy details or click Associated Proxy Services tab to view the proxy services associated with the policies
Select a policy, then click Assign to Proxy Services to assign a policy to the proxy services.
Click Add to add a TCP policy. The Add TCP Policy dialog box appears.
Select a policy, then click Edit to edit a TCP policy. The Edit TCP Policy dialog box appears.
Select a policy, then click Delete to delete the policy.
SSL Policy Details
Adding SSL Policies
Step 1 Click Setup from the task bar.
Step 2 Click Policies on the left-most pane, then select SSL Policy from the object selector. The policy information appears on the page.
Step 3 Click Add. The Add SSL Policy dialog box appears.
Step 4 Click OK to add the new SSL Policy.
Editing SSL Policies
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select SSL Policy from the object selector. The policy information appears on the page.
Step 3 Click Edit. The Edit SSL Policy dialog box appears.
Step 4 Click OK to apply the new values.
Deleting SSL Policy
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select SSL Policy from the object selector. The policy information appears on the page.
Step 3 Select a Policy from the list, then click Delete.
HTTP Header Insertion Policy
HTTP header insertion is performed for the following methods: GET, HEAD, PUT, TRACE, POST, DELETE. HTTP header insertion is not performed for the CONNECT method.
Note You can configure up to 100 HTTP header insertion policies, each policy consisting of up to 32 prefixes or headers. Prefix and custom headers can include up to 240 characters.
You can insert the following header types:
•Client Certificate Headers--Allow the backend server to see the attributes of the client certificate that the SSL module has authenticated and approved. Client certificate headers are sent only once per session. The server is expected to cache these values using the session ID, which is also inserted with the headers. In subsequent requests, the server uses the session ID to look up the cached client certificate headers on the server itself.
If the client does not send a certificate, the SSL handshake fails. There is no data phase or header insertion.
–Client IP and Port Address Headers
Network address translation (NAT) changes the client IP address and destination TCP port number information. When you specify Client IP Port, the SSL module inserts the client IP address and TCP destination port information in the HTTP header, allowing the server to see the client IP address and destination port number.
–Custom Headers
When you specify a custom string, the SSL module inserts the user-defined header verbatim in the HTTP header. You can configure up to 16 custom headers per HTTP header policy. The custom string can include up to 240 characters.
–Prefix
The SSL module adds the specified prefix to every inserted HTTP header. Adding a prefix enables the server to identify connections as coming from the SSL module, and not from other appliances. A prefix is not added to standard HTTP headers from the client. The prefix_string can be up to 240 characters.
•SSL Session Headers-- including the session ID, are used to cache client certificates based on the session ID. Session headers are also cached based on the session ID if the server wants to track connections based on a particular cipher suite. The SSL module inserts the full session headers in the HTTP request during full SSL handshake, but inserts only the session ID when the session resumes.
When you configure the SSL module as a client, the SSL module inserts the session ID of the connection between the module and the backend SSL server.
Viewing HTTP Header Insertion Policy
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select HTTP Header Insertion Policies from the object selector. The policy information appears on the page.
The following fields appear:
Fields DescriptionPolicy Name
Name of the policy.
Use Count
Number of proxy services using the policy.
Select a policy from the HTTP Header Insertion Policy table, then click Policy Tab to view the policy details or click Associated Proxy Services tab to view the proxy services associated with the policies
Select a policy, then click Assign to Proxy Services to assign a policy to the proxy services.
Click Add to add a new TCP policy. The Add TCP Policy dialog box appears.
Select a policy, then click Edit to edit a TCP policy. The Edit TCP Policy dialog box appears.
Select a policy, then click Delete to delete the policy.
Adding HTTP Header Insertion Policy
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select HTTP Header Insertion Policy from the object selector. The policy information appears on the page.
Step 3 Click Add. The Add HTTP Header Insertion Policy dialog box appears:
Step 4 Click OK to add the new policy.
Editing HTTP Header Insertion Policy
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select HTTP Header Insertion Policy from the object selector. The policy information appears on the page.
Step 3 Click Edit. The Edit HTTP Header Insertion Policy dialog box appears:
Step 4 Click OK to apply the modifications.
Deleting HTTP Header Insertion Policy
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select HTTP Header Insertion Policy from the object selector. The policy information appears on the page.
Step 3 Select a Policy from the list, then click Delete.
URL Rewrite Policy
The URL rewrite feature supports the rewriting of redirection links. The system scans only the Location: HTTP header field in the response from the server and rewrites the rules accordingly. The URL rewrite feature does not support embedded links.
The URL rewrite feature rewrites the protocol and the non-default port (default ports are port 80 for cleartext and port 443 for SSL).
Note You can configure up to 100 URL rewrite policies, each policy consisting of up to 32 rewrite rules per SSL proxy service, up to 200 characters per rule.
Follow these guidelines for URL rewrite:
•An exact URL match takes precedence over a wildcard rule. A suffix wildcard rule takes precedence over a prefix wildcard rule.
For example, www.cisco.com takes precedence, then www.cisco.*, then *.cisco.com.
•Enter only one suffix or prefix wildcard rule at one time. For example, do not enter www.cisco.* and www.cisco.c* in the same policy. Similarly, do not enter *w.cisco.com and *.cisco.com in the same policy.
•Do not enter two exact URL match rules in the same policy. For example, do not enter www.cisco.com clearport 80 sslport 443 and www.cisco.com clearport 81 sslport 444 in the same policy. In this case, the second rule entered overwrites the first rule.
•URL rewrite is performed for both offload and backend (HTTP-to-HTTPS, and HTTPS-to-HTTP). This includes port rewrites.
Viewing URL Rewrite Policy
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select URL Rewrite Policy from the object selector. The policy information appears on the page.
The following fields appear:
Fields DescriptionPolicy Name
The name of the URL-Rewrite policy.
Number of Proxy Services (Use Count)
Number of proxy services using the SSL Policy.
Select a policy from the URL Rewrite Policy table, then Click Policy Tab to view the policy details or click Associated Proxy Services tab to view the proxy services associated with the policies
Select a policy, then click Assign to Proxy Services to assign a policy to the proxy services.
Click Add to add a URL Rewrite Policy. The Add URL Rewrite Policy dialog box appears.
Select a policy, then click Edit to edit a URL Rewrite Policy. The Edit URL Rewrite Policy dialog box appears.
Select a policy, then click Delete to delete the policy.
Following are the URL Rewrite Policy details:
Adding URL Rewrite Policy
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select URL Rewrite Policy from the object selector. The policy information appears on the page.
Step 3 Click Add. The Add URL Rewrite Policy dialog box appears.
You can specify URL alone. But you cannot add clear port and SSL port without entering a URL value.
Note You can configure up to 32 rewrite rules per SSL proxy service, up to 240 characters per rule. You should enter only one suffix or prefix wildcard character (*) only once per rewrite rule.
To remove a URL Rewrite Rule, select the rule from the table, then click Remove.
Step 4 Click OK to add the new policy.
Editing URL Rewrite Policy
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select URL Rewrite Policy from the object selector. The policy information appears on the page.
Step 3 Select a policy, then click Edit. The Edit URL Rewrite Policy dialog box appears.
The following fields appear:
You can specify URL alone. But you cannot add Clear Port and SSL Port without entering a URL value.
Note You can configure up to 32 rewrite rules per SSL proxy service, up to 240 characters per rule. You should enter only one suffix or prefix wildcard character (*) only once per rewrite rule.
To remove a URL Rewrite Rule, select the rule from the table, then click Remove.
Step 4 Click OK to modify values.
Viewing URL Rules and Outcome
The URL Rules and Outcome dialog box helps you view the URL rules you have set and the outcome of the rules.
To view URL Rules and Outcome:
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select URL Rewrite Policy from the object All Router View. The policy information appears on the page.
Step 3 Select a policy from the table. The details appear on the URL Rewrite Policy Details pane. If you have set a URL rewrite for the policy, The View Rules and Outcome button will be active.
Step 4 Click View Rules and Outcome. The Rules and Outcome dialog box appears.
To view rules and outcome for server proxy, Click Rules and Outcome for Client Proxy tab. The following fields appear:
To view rules and outcome for server proxy, Click Rules and Outcome for Server Proxy tab. The following fields appear:
Deleting URL Rewrite Policy
To delete a policy:
Step 1 Click Setup from the task bar.
Step 2 Click Policies from the left-most pane, then select URL Rewrite Policy from the object selector. The policy information appears on the page.
Step 3 Select a Policy from the list, then click Delete.
Posted: Fri Apr 15 04:00:48 PDT 2005
All contents are Copyright © 1992--2005 Cisco Systems, Inc. All rights reserved.
Important Notices and Privacy Statement.