Forum Discussion
Michael_Koyfma1
Cirrus
May 12, 2005Bi-directional traffic cloning possible?
Is it possible to clone traffic bi-directionally using iRules. Clone Pool functionality is only uni-directional – ingress traffic on VIP is being cloned to another pool. But there is a desire to clone response from servers to the probe pool as well. Is it possible to do it using iRules(taking advantage of SERVER_DATA event?)
- unRuleY_95363Historic F5 AccountThis is not true, at least not intentionally. Clone pool functionality is bi-directional. It does clone both ingress and egress packets (at least that is how it is implemented). If this is not working for you, please contact support.
- So, are you saying that if I setup serverside pool cloning and terminate SSL on the BigIP, we will clone not only ingress traffic on the VIP to the clone pool but the response from the main server pool nodes as well? What happens if both ServerSide and CLientSide SSL profiles are used(i.e. BigIP terminates SSL, examines traffic, and then reencrypts and sends to the server? Is it possible to clone the unencrypted traffic? Thanks a lot once again.
- unRuleY_95363Historic F5 AccountYes, both ingress and egress gets cloned regardless of side.
- johns
Employee
As for serverside re-encryption - currently, the re-encrypted traffic gets copied to the clone pool (we clone at ip input/output). We do have a feature request already on file for being able to clone the unencrypted traffic when serverside re-encryption is in effect.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects