cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
370
Views
0
Helpful
2
Replies

SSL source IP

cisco123456
Level 1
Level 1

When using SSL modules in the CSS, does the client source IP address show up on the web server? Or does the CSS do a source NAT so the packet comes back to the SSL module?

2 Replies 2

Gilles Dufour
Cisco Employee
Cisco Employee

the client ip address is preserved.

That's why you need to make sure the response goes back to the CSS either by pointing the default gateway at the CSS pr by using some sort of policy routing.

Gilles.

stevehall
Level 1
Level 1

The SSL module does not have an IP address assigned to it, so it cannot use its own. The server should see the client IP address, unless you configure source nat specifically by using groups.

-Steve