Manual Chapter :
Configure device specific SSLO settings
Applies To:
Show VersionsBIG-IQ Centralized Management
- 7.1.0
Configure device specific SSLO settings
From BIG-IQ, you can modify the device configuration for a managed BIG-IP device and view the status of services deployed to a device, and deploy changes to this device.
- At the top of the page, view your services deployed in a topology on this device. To make any edits to security service configuration, select the name of the service and you will be directed to a page where you can make edits.
- From BIG-IQ, navigate to.
- Select a managed BIG-IP device from theDeviceslist.You will be directed to a page where you may configure SSLO BIG-IP device settings.
- UnderDevice Settings, specify whether you want this configuration to support IPv4 addresses or IPv6 addresses from the dropdown menu.You must configure IP addresses in the family you select for all IP address fields in this application.
- Under theDNSsection, select eitherInternet Authoritative Nameserverto permit the system to send DNS queries directly out to the Internet, you can selectLocal Forwarding Nameserver.Direct resolution can be more reliable than using forwarders but requires outbound UDP+TCP port 53 access to the Internet.
- Click the DNSSec Validation checkbox to specify whether you want to use DNSSEC to validate the DNS information.F5 reccomends using DNSSEC to validate DNS information as it improves security.
- If you selectedLocal Forwarding Nameserverin the above section, add one or moreLocal DNS Nameserverin the sectionLocal Forwarding NameServer(s).
- UnderRouting, selectDefaultto allow the system to let all SSL intercept traffic use the default route, or selectCreate Newto route the traffic through a custom Internet gateway. Add anAddressand specify theRatioto define the ratio of traffic sent to each device.
- Under theLogging Configurationsection, select a logging level for this device from the dropdown menu. You may select from Errors, Normal, or Debug.
- You may enable the default log configuration by selecting the checkbox. ForPer-Request Policy,FTP,IMAP,POP3,SMTPS, andSSL Orchestrator Generic(generic logs for the SSL Orchestrator configuration), select the level of severity that you would like to log for this data.
- SelectDeployto push changes to this managed device.
Your configuration changes will be deployed to the managed BIG-IP device.