Related, but not the same question as Should SSL be terminated at a load balancer?.
Our web stack looks like:
- Web Server – IIS
- Load Balancer – NetScalar
- Firewall – Palo Alto
- CDN/WAF – Akamai
- End client
What is the best practice for ensuring security while having the minimal number of TLS encrypts/decrypts?