Forum Discussion
Gary_Meehan_315
May 14, 2012Nimbostratus
Big-IP LTM Re-encryption
Hi all,
I've using the virtual edition of Big-IP 10.1 under a trial license, which I'm using to load balance traffic to a web server (a single instance of IIS in my test case).
In my virtual server, I can specify a client SSL Profile, so that the Big-IP server receives HTTPS traffic decrypts it and sends HTTP traffic to the web server, working fine. I can also specify a server SSL profile, so the Big-IP server receives HTTP traffic and sends HTTPS traffic to my web server, working. However, when I set both client and server SSL profiles, I never get a response to my requests.
I want the Big-IP server to decrypt incoming traffic, add a cookie for persistence profiling, and re-encrypt the traffic before sending it on to the web server. I can see the request coming into the web server but no response is ever seen at the browser.
I was wondering if anybody had any ideas on how I can get this working. I have self-signed certificates on both the Big-IP server and the web server if that makes any difference.
Thanks,
Gary
- SteveMPNimbostratusFor the SSL profiles, did you add the certificate AND the key? And does either one require a chain? Also, did you set the client machine to trust the self signed cert?
- Gary_Meehan_315NimbostratusHi Steve,
- John_Matlock_42NimbostratusHi Gary,
- Gary_Meehan_315NimbostratusHi John,
- John_Matlock_42NimbostratusHmm, I probably responded to this too early in the morning as I apparently didn't read your entire post. I apologize for that.
- SteveMPNimbostratusJust curious, did you run the IIS template to set this up?
- Gary_Meehan_315NimbostratusSteve, I've tried both the Generic HTTP template and the IIS one, both with the same result. Currently, I'm using the a setup based on the Generic HTTP profile from a fresh installation from the VM template.
- John_Matlock_42NimbostratusGary,
- Gary_Meehan_315NimbostratusThanks, John. Not had chance to get any tcp dumps from the Big-IP box: I'll have to consult with a colleague who has more knowledge of Linux networking than I do. I have run Wireshark on the web server and the traffic looks okay that end. Looks like it's using TLS v1.0.
- Lloyd_56248Historic F5 AccountPersonally I wouldn't use the trial edition as some features are not complete:
Recent Discussions
Related Content
Â
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects