Troubleshooting guide

1-30
Cisco Wide Area Application Services Configuration Guide
OL-26579-01
Chapter 1 Configuring Application Acceleration
Enabling and Disabling the Global Optimization Features
Figure 1-14 SSL Acceleration Block Diagram
When you configure SSL acceleration, you must configure SSL accelerated service on the server-side
(Data Center) WAE devices. The client-side (Branch) WAE needs to have its secure store initialized and
unlocked/opened, but does not need to have the SSL accelerated service configured. However, the SSL
accelerator must be enabled on both Data Center and Branch WAEs for SSL acceleration services to
work. The WAAS Central Manager provides SSL management services and maintains the encryption
certificates and keys.
Enabling Secure Store, the Enterprise License, and SSL Acceleration
Before you can use SSL acceleration on your WAAS system, you must perform the following steps:
Step 1 Enable secure store encryption on the Central Manager.
To enable secure store encryption, see the “Configuring Secure Store Settings” section on page 1-10.
Step 2 Enable the Enterprise license.
To enable the Enterprise license, see the “Managing Software Licenses” section on page 1-3.
Step 3 Enable SSL acceleration on devices.
To enable the SSL acceleration feature, see the “Enabling and Disabling the Global Optimization
Features” section on page 1-3.
Central Manager
Branch WAE
Branch WAN
Router
Client Server
Common Name =
hr.analog.com
WAE to WAE
Peering Service
Client to Server
Accelerated Service
SSL Data
SSL Sessions
SSL Service - TCP connection carrying SSL
traffic on a well known TCP Prot (e.g. 443)
TCP Session
Core to Server SSL
Session
Client to Data Center SSL
Session
WAN1
Data Center WAE
Admin Browser CM Administration
Admin Service
CM to Br
anch WAE
Management Service
CM to Data Center WAE
Management Service
243495
Data Center WAN
Router