THE PROBLEM
Encryption does not mean content is safe. There is a high risk that threats enter the perimeter via secure transactions—hackers embed malicious code in encrypted web server requests.
Therefore, requests to web servers must be screened by an intrusion detection solution and for this to work on secure traffic SSL decryption should be moved from web servers to the perimeter of the firewall.
SOLVING THE PROBLEM
Datacenter firewalls protect your hosting infrastructure already at the perimeter. When placing certificates from the secure webservers into the perimeter firewall it enables the firewall to terminate SSL traffic and perform deep screening.
This is non-intrusive as the web-surfing customer session is terminated using the legitimate certificate, and after scanning it’s traffic is forwarded transparently to the web server. Traffic forwarded to web server can be sent unencrypted, saving resources on web server farms.
THE RESULT
Enabling SSL traffic inspection for incoming traffic to your server farm provides a higher level of protection. It allows for screening inside the encrypted traffic and search for threats that would otherwise be invisible. The reduced footprint cost by moving decryption to high performance firewalls is an added benefit to reduce costs. Inspecting traffic destined for your secure server farm mitigates risks but can also offload and increase performance.
1
Higher level of protection for web server farms by screening encrypted traffic
2
Enabling Intrution Detection and Prevention routines detecting threats otherwise invisible
3
Reduced footprint cost by moving decryption to high performance firewalls
Solutions & Customers
The following solutions and customers benefit from this use-case:
SOLUTION
Border Gateway Roaming Security
Protect the connections from
other operators
SOLUTION
Service Domain Security
Protect business critical systems within the core network
SOLUTION
Protection of Legacy Systems
Secure corporate resource usage and manage employee time