SSL Offloading

Another common methodology in reverse proxy scenarios is to use SSL offloading. In this scenario, the client’s SSL tunnel terminates at the reverse proxy, which then initiates a clear-text, HTTP request to the internal resource. Many hardware load balancers offer this functionality and advertise that it can improve performance of servers by “offloading” the SSL encryption and decryption duties from the internal server.

This is a valuable feature when a server is CPU-constrained, but with modern hardware, this is rarely necessary. Any hardware used for Lync Server probably far exceeds the CPU capabilities of most load-balancing devices. Furthermore, Lync Server is designed to operate in a secure manner end-to-end and does not actually support SSL offloading. However, in this scenario the SSL tunnel is terminated at the reverse proxy, which then communicates over port 80 to the Front End pool, leaving an unencrypted component.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset