Forum Discussion
hui_37443
Jun 29, 2012Nimbostratus
authentication timeout
I've noticed that OCSP responder never times out. I've managed to make a dummy OCSP server which receives a request & goes to sleep. F5 keeps waiting for the response that never comes back. That make...
hooleylist
Jun 29, 2012Cirrostratus
If you have more than one OCSP server, it would also be good to configure them in a pool and add that to an internal virtual server. You could then configure that internal VS as the OCSP responder IP:port.
With or without an OCSP virtual server, you could configure a pool containing the OCSP server(s) with a health monitor and check for [active_members ocsp_pool] > 0 before attempting the auth from the OCSP iRule. This will help you avoid attempting auth if the OCSP server(s) are unreachable.
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects