Forum Discussion
julian_mata_164
Nimbostratus
Mar 26, 2015Capturing the Source IP?
So I've read about this and still can come up with a solution.
Our current set up is a VIP with Source Address Translation set to AutoMap.
We need to get the Source IP via the Webserver.
Iv...
Brad_Parker
Cirrus
Mar 26, 2015What doesn't work when you enable X-Forwarded-For? Is your site HTTP or HTTPS?
- julian_mata_164Mar 26, 2015
Nimbostratus
Site is https. - Brad_ParkerMar 26, 2015
Cirrus
The problem you are having is that to apply an HTTP profile to an HTTPS site requires a client SSL profile. Otherwise all your connections will get reset. I would consider SSL offloading, but at a minimum you do need a client SSL profile. If you need end to end encryption you can add a server SSL profile. - julian_mata_164Mar 27, 2015
Nimbostratus
Would the default clientssl work for SSL Profile (Client) I just added this one and site wont respond. - Brad_ParkerMar 27, 2015
Cirrus
Yes, the default client SSL profile will "work", but you will get a cert error in the browser. Even with the cert error you can test the connectivity to the site after accepting the warning. In Production you will need to put certificate and private key for the site loaded on the Big-IP. Don't know if this is the forum to exhaustively explain SSL profiles, but the links below should help. If you are going to SSL offload(client SSL only) you backedend servers will need to listen on HTTP not HTTPS. If you want the connection to the backend servers to be HTTPS, you will also require a server SSL profile. https://support.f5.com/kb/en-us/solutions/public/14000/700/sol14783.html https://support.f5.com/kb/en-us/solutions/public/14000/800/sol14806.html https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-ssl-administration-11-6-0/4.html - julian_mata_164Mar 27, 2015
Nimbostratus
Thank you for all the help. Looks like the only way for the siteto work is to add the SSL Profile(client) and SSL Profile(Server) defaults. But I will start reading the links and start looking into adding the Cert and PK. Thanks again.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects