Forum Discussion
smouzakis
Nimbostratus
Aug 13, 2017Block HTTPS URLs using Performance L4 VS
Hi,
Is it possible to block traffic based on http host using performance l4 virtual server using it as transparent proxy?
Source IP: 0.0.0.0
Destination IP: 0.0.0.0
Port: 443 (https)
Best R...
Stanislas_Piro2
Cumulonimbus
Aug 15, 2017If you really require Performance L4 feature, you can filter on SNI header instead on host value. When a client initiate a SSL negotiation, it can send a TLS header named Server Name.
current browsers send this header with the value of the Host header (IE on Windows XP does not, new versions does it). look at this thread to check Server Name header.
I never tried to use TCP::collect in performance L4 VS. You can try this solution and update this thread if worked (or not :-) ).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects