1 Answer
- Newest
- Most votes
- Most comments
0
Very good question and youve got me thinking...
- Yes. It needs to terminate and decrypt the HTTPs connection otherwise it will not be able to inspect the packets.
- No. The FW will re-encrypt the packets to the ALB. These are transparent in the path of the client. Just like a transparent proxy server.
Relevant content
- asked 7 months ago
- asked 2 years ago
So for point no -2 --> Are you saying no certificate at all require for ALB to terminate SSL connection ?
You will still need a valid cert on the ALB which the Firewall trusts for end to end encryption
Thanks, so i assume, it can be any private certificate on ALB works ?