Forum Discussion
cbarnett_13782
Nimbostratus
Feb 16, 2009Block ssl requests by ip
We need to test out a website befor we roll it out to production. So to test we want to only allow certian IP addresses accessing a virtual server. I have this working nicely for the HTTP virtual serv...
cbarnett_13782
Nimbostratus
Feb 16, 2009I have three pools, one for 80, one for 443, and one for 8080. The only one that works with the SSL VIP is the 443 pool.
Without the rule
[root@F51:Active] log b virtual WWWSSH list
virtual WWWSSH {
destination ipaddress:https
ip protocol tcp
pool WEBPOOLSSH
vlans external enable
}
[root@F51:Active] log b pool WEBPOOLSSH list
pool WEBPOOLSSH {
monitor all https
member 10.100.74.15:https
member 10.100.74.16:https
}
With the irule
[root@F51:Active] log b virtual WWWSSH list
virtual WWWSSH {
destination ipaddress:https
ip protocol tcp
pool WEBPOOLSSH
rule Block_all_but_us_NEW
vlans external enable
}
[root@F51:Active] log b pool WEBPOOLSSH list
pool WEBPOOLSSH {
monitor all https
member 10.100.74.15:https
member 10.100.74.16:https
}
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
