Securing Encrypted (SSL) Web Traffic

As the World Wide Web was maturing, organizations realized that if they encrypted the HTTP packets that were transmitted between a website and a client, it would make it virtually unreadable to anyone who would potentially intercept those packets. This led to the adoption of SSL encryption for HTTP traffic.

Of course, encrypted packets also create somewhat of a dilemma from an intrusion detection and analysis perspective, because it is impossible to read the content of the packet to determine what it is trying to do. Indeed, many HTTP exploits in the wild today can be transmitted over secure SSL-encrypted channels. This poses a dangerous situation for organizations that must secure the traffic against interception but must also proactively monitor and secure their web servers against attack.

The Forefront Edge line is uniquely positioned to solve this problem, fortunately, because it includes the ability to perform end-to-end SSL bridging. By installing the SSL Certificate from the SharePoint web front-end server on either the Forefront UAG or Forefront TMG servers, along with a copy of the private key, the server is able to decrypt the traffic, scan it for exploits, and then re-encrypt it before sending it to the SharePoint server. Very few products on the market do this type of end-to-end encryption of the packets for this level of security other than the two Forefront Edge line products. Before Forefront UAG or Forefront TMG can secure SharePoint SSL traffic, however, an SSL Certificate must be placed on the SharePoint server.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset