It doesn't sound much like off-loading at that point does it? :)
So you utilize the SSL-Offloading setting on the F5 to unencrypt the traffic and then have F5 re-encrypt the traffic before sending it to the CAS array. The CAS array will still have to unencrypt the traffic.
From a performance gain stand-point, you don't gain anything from this so you aren't really off-loading.
If your security team is concerned, are they concerned about difference security standards or certifications being met (outside of being able to get to mailbox data on port 80)? I can't really agree with their concern and I know that SSL-Offloading
meets PCI, HIPAA, FISMA, etc. standards. The traffic is also on the internal network at this point (and possibly on its own subnet behind the F5) so how many users have access AND knowledge to get at the traffic?Jason Apt Microsoft Certified Master | Exchange 2010
There is an amazing pack of free network admin tools.
click here to download it