Forum Discussion

Amit585731's avatar
Amit585731
Icon for Nimbostratus rankNimbostratus
Sep 21, 2018

SSL Orchestrator

Hi All,

 

just want to understand the difference between ssl orchestrator on LTM and herculon model? The only difference is herculon consist of ssl orchestrator + hybrid ddos protection? While LTM can still function for ssl offloading?

 

What does this sslo 4 refer to and how this is different from BIGIPv14?

 

THanks.

 

1 Reply

  • There are a few things to note here.

     

    • First and most important, the Herculon brand is going away: https://support.f5.com/csp/article/K63201409, so Herculon SSLO users should start migrating to the new SSL Orchestrator platform. In most cases that's just a software update to your existing Herculon hardware.

       

    • Fundamentally, Herculon ran a version of SSL Orchestrator called "3.0". That is being replaced with the 4.0 version, which now comes installed on BIG-IP 14.0.

       

    • The previous Herculon, or "SSL Forward Proxy" license has also been replaced with a (backwards compatible) "SSL Orchestrator" license. If you're running on a v12 or v13 platform today with SSL Forward Proxy, you can upgrade that to the new license and continue doing what you're doing now, but it'll make migrating to a later version much easier when you're ready.

       

    • SSL Orchestrator 4.0 is a vastly improved version of the product that now contains (among many other new things) the following features:

       

      • Inbound and outbound traffic inspection (forward and reverse proxy)
      • A transparent "bump-in-the-wire" mode
      • The ability to insert an HTTP proxy (any vendor's proxy) into the decrypted inspection zone
      • Service chaining and traffic classification configurable via visual policy (similar to an Access per-request policy)
      • Further optimizations and throughput enhancements
      • Additional iRules customization support