F5 and similar

From: pen test (pentestlistat_private)
Date: Tue Aug 26 2003 - 18:55:55 PDT


Recently I started a pen test of a network and the company is using a F5 
BigIP for load balancing and ssl acceleration.  I looked and looked and 
could not find any information to answer a few questions. Any help would be 
great.

Does the BigIp handle all requests and stay between the client and server or 
does it just simply redirect to the server?

Bascially what I am getting at is if the the BigIp is between the client and 
application server

client ---ssl--- bigip ---http--- application server

is the the application server safe from attacks that may affect it as the 
bigip will actually be on the one that is attacked?

Thanks

_________________________________________________________________
Get MSN 8 and enjoy automatic e-mail virus protection.    
http://join.msn.com/?page=features/virus


---------------------------------------------------------------------------
FREE Trial!
New for security consultants and in-house pros: FOUNDSTONE PROFESSIONAL 
and PROFESSIONAL TL software. Fast, reliable vulnerability assessment 
technology powered by the award-winning FoundScan engine. Try it free for  21 days at: http://www.securityfocus.com/sponsor/Foundstone_pen-test_030825
----------------------------------------------------------------------------



This archive was generated by hypermail 2b30 : Tue Aug 26 2003 - 20:08:23 PDT