Solved

Forefront Threat Management Gateway - SSL Decryption

Posted on 2011-03-03
5
1,047 Views
Last Modified: 2013-11-16
Hi,
Does the Microsoft Forefront Threat Management Gateway (and other ISA version) have SSL decryption (interception) abilities that allows one to drop other equipment into the SSL decrypted zone?

Thank you for your insight.
0
Comment
Question by:NYGiantsFan
  • 3
  • 2
5 Comments
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 35027731
ISA does not - FTMG does - the service is called https inspection.
I am not clear though on what you mean by 'that allows one to drop other equipment into the SSL decrypted zone' - can you explain further?

For reference, https inspection is a double-edged sword. What it does is allow FTMG to inspect SSL traffic by terminating the SSL connection and then the FTMG creates its own SSL connection to the destination in effect making two SSL bridges. However, this can also have legal ramifications.... For example, one of your users makes an SSL connection to his bank to transfer funds and you are breaking that SSL connection to 'inspect' traffic.... think about it.

Also, a number of ssl sites will cease to operate if https inspection is applied to them, Microsoft's own update sites are included in this list.

Keith
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 35027758
As an extra, https inspection is just being amended in FTMG 2010. A new update has just been released (rollup 3 for SP1), you may want to get this installed as well.
http://support.microsoft.com/kb/2498770

Keith
0
 

Author Comment

by:NYGiantsFan
ID: 35035994
Hi,

What I mean in dropping additional equipment, lets say we wanted to drop an IDS or malaware detector into the decrypted zone?  Appliances exist that just decrypts traffic so you can plug such devices into it.  Blue Coat does not allow you to plug additional hardware into the decrypted stream, Netanome does.  I was wondering if FTMG does.

As for laws, we don't need no stinking laws.  (Just kidding, it is covered)
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 500 total points
ID: 35036022
I see - No FTMG would not do that. The break in the https stream is within the FTMG application where it is terminated, inspected and then recreated by FTMG using its own copy of the certificate through to the destination.

Keith
0
 

Author Closing Comment

by:NYGiantsFan
ID: 35036069
Thanks!
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

By default, Carbonite Server Backup manages your encryption key for you using Advanced Encryption Standard (AES) 128-bit encryption. If you choose to manage your private encryption key, your backups will be encrypted using AES 256-bit encryption.
Many companies are looking to get out of the datacenter business and to services like Microsoft Azure to provide Infrastructure as a Service (IaaS) solutions for legacy client server workloads, rather than continuing to make capital investments in h…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question