Forum Discussion
Adding 2 client-ssl in 1 virtual.
Is there a way we can associate two client-ssl profile to one virtual? If yes then how?
- Samir_Jha_52506
Noctilucent
You can add more then 2 SSL profile in VIP either via iRule calling or SNI setting.
- Kevin_Stewart
Employee
If I may elaborate, it's the server name attribute in the client SSL profile. Presumably each client SSL profile would possess a different server certificate, with a unique subject and/or subject alt name value. By setting the server name field in each client SSL profile to match the certificate's subject name, the F5 can effectively switch between the client SSL profiles based on the Server Name Indication extension in a client's TLS Client Hello message (start of the TLS handshake).
You'll also need to enable the "Default for SNI" option on one of these profiles, in the event that the client does not present an SNI.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com