
Allow SSLv3 Enables SSLv3 for client connections.
Software SSL Only
(E450GX & E650GX only)
When disabled (default), an HTTPS cluster performs hardware SSL
acceleration using the version of OpenSSL supported in previous releases.
When enabled, an HTTPS cluster uses the updated version of OpenSSL
(1.0.1e).
Click on Commit to save changes to the cluster configuration.
Server Name Indication
Server Name Indication (SNI) is an extension to the SSL and TLS protocols that indicates a server name or
website that a client is attempting to connect with at the start of the handshake process. It allows a server to
present multiple certificates on the same IP address and port number, thus allowing multiple secure (HTTPS)
websites to be served off of the same IP address while allowing all of those sites to use the same certificate.
SNI objects are added to certificates that are in the certificate store on Equalizer and are configured on HTTPS
clusters.After a client connects with a TCP port on Equalizer, Equalizer searches it's certificate store for the
website name that was exchanged as part of the HTTPS packet header. If the website is NOTpresented on a
certificate, the cluster's default certificate will be returned to the client. If the website ISpresented on a
certificated, that certificate will be returned to the client. Using SNI, additional websites are associated with
certificates allowing a certificate to be returned to a client for multiple website requests, thus minimizing the need
to purchase costly wild card certificates.
The following illustration shows the connection and certificate process with Equalizer and an HTTPS cluster:
Note - An SNI sub object can be created for HTTPS clusters on Equalizer E450GX or E650GX only
Server Name Indication Using the GUI
Proceed with the following to configured SNI certificates on an HTTPS cluster using the GUI:
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
All Rights Reserved.
299
Equalizer Administration Guide
Comentarios a estos manuales