Forum Discussion
ardmallor
Jan 22, 2021Nimbostratus
Citrix SSL GW VIp
Have a question here that may seem remedial however having challenges creating a custom VIP on a F5 where SSL is decrypted, sent in the clear to some security reverse proxy devices (if the traffic wa...
Jan 23, 2021
Hi,
You can create two virtual servers. One with port 443, ssl offloading and pool pool-rp, another with port any (with same destination ip) and pool pool-ctx-direct.
All 443 traffic will go to the 443 virtual server, all other traffic to the any virtual server.
Cheers,
Kees
- ardmallorJan 23, 2021Nimbostratus
Yes we considered this with a 444 port however this would allow all traffic(http and non-http) to be attacked directly towards that Citrix gw direct and remove our ability to inspection/block traffic (number of citrix http vpn attacks)
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects