Firewall Wizards mailing list archives

Re: question on securing out-of-band management (ver. 2)


From: Dave Piscitello <dave () corecom com>
Date: Thu, 09 Feb 2006 13:06:23 -0500

golovast wrote:
If the appliance is essentially an SSL proxy, the problem is that the traffic between the appliance and the servers is not encrypted.

I must have been half-asleep when I first read this.

Some SSL proxy implementations (VPN appliances) allow you to chain SSL traffic:

- user negotiates and uses SSL to the proxy
- proxy negotiates and uses SSL to servers

VOIP also uses this technique to protect SIP from UA to proxy servers and from proxy to proxy across SIP domains.

Attachment: dave.vcf
Description:

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature


Current thread: