Forum Discussion
Building a proxy to reach out to an internet based SSL server
What we would like to do is setup a VIP in BIG-IP that will accept HTTP requests from the client, and forward those requests to an HTTPS internet server. The SSL Handshake is incomplete. The Client Hello occurs but there is no Server Hello.
1) The virtual has an iRule to rewrite the host name on HTTP_REQUESTs (proxy.local.domain.ca ==> site.domain.name.ca) 2) The CN on the cert returned (ssl2016.domain.name.ca), when going directly to the site, does not match the Host in the request (site.domain.name.ca).
Can we accomplish this?
Patrick
1 Reply
- Brad_Parker
Cirrus
If the site you are connecting to requires SNI that could be causing your observed behavior. If that is the case you will have to look into using a server SSL profile that has the Server Name property defined for the site you are trying to connect to.
https://support.f5.com/kb/en-us/solutions/public/14000/800/sol14806.html
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com