Forum Discussion
spurushothaman_
Nimbostratus
Apr 25, 2016Client/Source IP is not passed to downstream application
I have VIP in F5 SNAT with x-forward enabled - but SSL is terminated at the backend. We have http profile is set none to make the client mutual authentication to work along with SSL.
How do I...
Ryannnnnnnnn
Altocumulus
Apr 25, 2016I guess it depends on how you've designed your environment, but at a minimum you need to allow the BIG-IP to be able to see "inside" the encrypted traffic. You can do this by either SSL offloading or SSL bridging, you can then enable a http profile with the insert x-forwarded-for option enabled.
- spurushothaman_Apr 26, 2016
Nimbostratus
SSL bridging is deprecated because of the security vulnerability. - RyannnnnnnnnApr 26, 2016
Altocumulus
What vulnerability, can you elaborate please?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects