SSL WAN Optimization Certificates
Configuration > Overlays & Security > SSL for WAN Optimization > SSL WAN Optimization Certificates
EdgeConnects provide deduplication for SSL-encrypted WAN traffic by supporting the use of SSL WAN Optimization certificates and other keys. An EdgeConnect decrypts SSL data using the configured certificates and keys, optimizes data, and transmits data over an IPSec tunnel. The peer EdgeConnect uses configured SSL WAN Optimization certificates to re-encrypt data before transmission.
-
Peers that exchange and optimize SSL traffic must use the same certificate and key.
-
For the SSL WAN Optimization certificates to function:
-
Tunnels must be in IPSec or IPSec UDP mode for both directions of traffic.
-
TCP acceleration and SSL acceleration must be enabled in the Optimization Policy.
-
The SSL WAN Optimization Certificates tab summarizes the SSL WAN Optimization certificates installed on appliances for decrypting non-SaaS traffic.
TIP: For a historical matrix of EdgeConnect and Orchestrator security algorithms, view the Security Algorithms PDF.
SSL WAN Optimization Certificates Dialog Box
Use the SSL WAN Optimization Certificates dialog box when the server is part of your enterprise network and has its own enterprise SSL certificates and key pairs.
Use this dialog box to load the certificate and key directly into the appliance.
-
You can add either a PFX certificate (generally, for Microsoft servers) or a PEM certificate. If the PFX Certificate File check box is not selected, the default certificate is PEM.
-
If the key file has an encrypted key, enter the passphrase needed to decrypt it.
Before installing the certificates:
-
Configure the tunnels bilaterally for IPSec mode.
To do so, navigate to Configuration > Networking > Tunnels > Tunnels, and then click the edit icon for the appropriate tunnel. The Tunnels dialog box opens. Click the edit icon for the appropriate tunnel, and then set the Mode field to IPSec.
-
Verify that TCP acceleration and SSL acceleration are enabled.
To do so, navigate to Configuration > Templates & Policies > Policies > Optimization Policies, and then review the Set Actions.