Hello,
We're about to switch to an ASG box to replace our juniper hardware. We're running an IIS webserver behind it that only allows https over port 443.
Will the ASG be able to do IPS on the https traffic? Or do we need an ssl offloading device that routes the decrypted data through the ASG again (if so, how do we maintain the source ip's of the IPS alerts?)
Same question for the advanced web application security features of the ASG (form hardening, xss/sqlinj. prevention, etc).
Thanks & regards,
Tim
This thread was automatically locked due to age.