Forum Discussion
Configure 2 URLS on same VIP and 2 SSL certificate
Hi Experts,
We are running LTM on version 11.2.1 . Please assist on how to configure 2 website URLS on same VIP with each URL having individual "SSL certificate" applied to it .Is it possible that we assign multiple client SSL profile to a Virtual Server . Although technically it is possible , however i am not sure if it works fine
Regards,
Ankur
10 Replies
- Matt_Dierick
Employee
Have a look : https://devcentral.f5.com/questions/multiple-ssl-client-profiles-for-one-virtual-server
Make sense ?
- Michael_Jenkins
Cirrostratus
While I haven't done this myself, I've done a little research on it, and I think what you're looking for is SNI (Server Name Indication). SOL3452 talks about setting up a VIP with SNI, and this article talks about it as well.
You'll have to operate under the assumption that all your clients are using a browser (client) support SNI.
- THi
Nimbostratus
There is a technical article on DevCentral on SNIs: https://devcentral.f5.com/articles/ssl-profiles-part-7-server-name-indication . I have a customer using SNI with two client profiles and it works fine with modern browsers.
Have a look on it. Also the whole article series may be worth reading.
- InnO
Nimbostratus
Done it, SNI is very easy to implement. For each SSL Client Profile you want to link to your VIP, just select Advanced settings, jump to Server Name. Enter the FQDN of your url in that field (myhost.mydomain.com). This is where the segregation between muliple profiles will occur.
One thing : one of your CLient SSL profiles must have the Default SSL Profile for SNI checked.
And like previous posts state about, the browser used need to support SNI.
- Ankur_5273
Nimbostratus
Hi All
Thanks for the suggestions ; however would like to know how do i ensure that all clients are using a browser (client) support SNI ?
Regards
Ankur
- InnO
Nimbostratus
- Ankur_5273
Nimbostratus
Hi
thanks again for the reference . Consider there are multiple client SSL and Server SSL Profile tied to the same Virtual Server . Hence in that case will the client SSL Profile (eg:ClientProfA) automatically match its corresponding Server SSL profile (eg:ServerProfA) ?
Ankur
- InnO
Nimbostratus
Server SSL Profiles also have a custom field for Serve Name Indication, so yes, it should match.
However, I never had to play with multiple Server SSL profiles linked to a single VS as most of the time here, our Big-IPs are simple clients to the back-end servers and therefore the simple and default serverssl profile is enough.
- Ankur_5273
Nimbostratus
Hi ,
1) As mentioned in above posts "One of your CLient SSL profiles must have the Default SSL Profile for SNI checked" .If i have 3 Client SSL Profiles on one VIP, does that mean in one of the profile i have to select "Server Name " and "Default SSL Profile for SNI " both ?
Also , if the website is www.myportal.com then FQDN of URL to be filled in the "Server Name" should be portal.com ?
2) Consider case of multiple Client and Server SSL profiles. For every Client SSL profile with a specific "Server Name " option filled in , do i have to mention the same "Server Name " in the corresponding Server SSL profile as well ?
Ankur
- Ankur_5273
Nimbostratus
Hi Experts,
Can you please let me know the following
1) As mentioned in above posts "One of your CLient SSL profiles must have the Default SSL Profile for SNI checked" .If i have 3 Client SSL Profiles on one VIP, does that mean in one of the profile i have to select "Server Name " and "Default SSL Profile for SNI " both ?
Also , if the website is www.myportal.com then FQDN of URL to be filled in the "Server Name" should be myportal.com ?
2) Consider case of multiple Client and Server SSL profiles. For every Client SSL profile with a specific "Server Name " option filled in , do i have to mention the same "Server Name " in the corresponding Server SSL profile as well ?
Regards,
Ankur
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com