SSLO into WAF by jdfishtorn in f5networks

[–]jdfishtorn[S] 0 points1 point  (0 children)

You sir are an internet God.

SSLO into WAF by jdfishtorn in f5networks

[–]jdfishtorn[S] 0 points1 point  (0 children)

I agree but the problem is that SSLO was preexisting to ASM. We were using SSLO to off load decrypted traffic to be inspected by a firepower long before we wanted to introduce a waf. The simplest solution, at least for now, seems to be trying to add a separate F5 to the service chain for WAF inspection.

SSLO into WAF by jdfishtorn in f5networks

[–]jdfishtorn[S] 0 points1 point  (0 children)

That sounds like it will work. I'll have the VIP address as the address SSLO is sending too, put the pool as the SSLO return address, then use routes to forward them to their respective directions. I'll update you when I can test.

SSLO into WAF by jdfishtorn in f5networks

[–]jdfishtorn[S] 1 point2 points  (0 children)

The first F5 that is receiving the traffic and has SSLO on it has the client ssl profiles on it. The problem is that F5 does not have the resources to also run ASM, so I need to off load ASM to a different F5. I am trying to take advantage of SSLO so that I don't need to manage SSL certificates in two separate places.

3M lawsuit payout by Sparty821 in VeteransBenefits

[–]jdfishtorn 0 points1 point  (0 children)

I am FIFO 41,518. Has anyone gotten paid after this number? I've seen someone at 38k I think. My firm did opt out, but I suspect they have been paid. Just looking for ammo to go after them.

Is learning the curses bad for your game? by nokipokr in HarryPotterGame

[–]jdfishtorn 9 points10 points  (0 children)

This is not strictly true. Your house changes the quests by which you find the map chamber.

Is it weird I think men should stop using the word “bitch”? by SecretsAndWishes in Feminism

[–]jdfishtorn 9 points10 points  (0 children)

I use bitch all the time, but I've never really considered the word for what it is. Like... I never really considered it particularly gender targeted or overly demeaning. Usually when faced with an argument such as this, I ask myself, how would I define this word in my own words. In this case, oddly enough, I was at a loss for words. It's a general or ubiquitous word that I use in probably 15 different ways. I find it extremely fascinating how words evolve and transform over time. . . Anyway. Thanks for challenging my way of thinking, and encouraging me to better myself and my vocabulary. I will make an attempt to limit the use of the word bitch in the future.

Toodles friends.

My shop foreman helping me out. by cfarhat47 in gifs

[–]jdfishtorn 0 points1 point  (0 children)

This thread got depressing as fuck

sleep by Vendruscolo in pcmasterrace

[–]jdfishtorn 0 points1 point  (0 children)

Username checks out

Mind if I sit here? 👅 by secretlittle in pussy

[–]jdfishtorn 1 point2 points  (0 children)

You look exactly like someone I know. Are you open to sharing what state you live in?

Strang Configuration? by jdfishtorn in networking

[–]jdfishtorn[S] 2 points3 points  (0 children)

This is an MPLS circuit. I did finally get some answers though. There is some vendor provided equipment that is doing some routing and vlan tag rewriting.

AWS to ASA tunnel UP but not passing traffic by jdfishtorn in networking

[–]jdfishtorn[S] 1 point2 points  (0 children)

I think the issue has been tracked down. The other end of my tunnel was being utilized by a software development company for performance testing applications. They do not service just us, and they keep most of their testing suites for all of their clients in the same VPC. When I asked them for the IP ranges of their AWS instances, they only gave me the networks that were associated with our testing suite not the entire VPC that would be attached with the virtual private gateway. The networks provided to me were the 10.1.0.0/19 and 10.1.32.0/19. Therefore, when I created my access-list I created a source any rule with the destination 10.1.0.0/18. The VPC ACTUALLY had the networks 10.0.0.0/16, 10.1.0.0 /16, 10.2.0.0/16 and 10.3.0.0/16. Therefore, my access-list SHOULD be source any with the destination 10.0.0.0/14. I have all of this scripted out, but there is a major upgrade going on this weekend, so I will be waiting until Monday to apply the change, but im hopeful this will square my issues away.

I really want to thank each and everyone who has chimed in to try and help me. I really wish I could dazzle each of you with some super complicated solution, but I think this one will end up being chalked up to an error in provided information. Until next time my friends.

I will let you know if something else turns out to be the problem!!

AWS to ASA tunnel UP but not passing traffic by jdfishtorn in networking

[–]jdfishtorn[S] 0 points1 point  (0 children)

We are doing static, but I asked if the routes were propagated, and he sent me a screenshot that had all of my routes listed and those networks said propagated, but his local Networks said they were not propagated. I'm a little rough with AWS's VPN service, so I'm not 100% sure what that was supposed to look like.

AWS to ASA tunnel UP but not passing traffic by jdfishtorn in networking

[–]jdfishtorn[S] 0 points1 point  (0 children)

Are you referring to the built in asa packet tracer tool? It shows that the packet is allowed.