Forum Discussion
cookie persistence for HTTPS traffic
I am looking for a option to set cookie persistence for HTTPS traffic.
I know cookie persistence will work only with HTTP profile, but I am wondering is there any way we configure cookie persistence for HTTPS traffic?
-Akhilesh
9 Replies
- nathe
Cirrocumulus
Akhilesh,
If you terminate the SSL connection at the bigip with a client ssl profile and you also have an http profile assigned to the VIP, then you will be able to use cookie persistence.
Hope this helps,
N
- nathe
Cirrocumulus
Akhilesh,
If you terminate the SSL connection at the bigip with a client ssl profile and you also have an http profile assigned to the VIP, then you will be able to use cookie persistence.
Hope this helps,
N
- Akhilesh_128432
Nimbostratus
I agreed, but in this case basically all the traffic from F5 to APP server would be http, right?.
-Akhilesh
- nathe
Cirrocumulus
you can re-encrypt to the backend app server using a server ssl profile - the default one (serverssl) should suffice.
- Akhilesh_128432
Nimbostratus
I have already one certificate installed on my application server, so do we need to assign my application certificate to serverssl profile?
- nathe
Cirrocumulus
export this and the key to the bigip and create a custom client ssl profile, inc. this cert/key to decrypt the traffic. the bigip can then use the default serverssl profile to re-encrypt.
- Kevin_Stewart
Employee
If I may add, the certificate that you use on the server side are less important. The default settings for the server SSL profile are to ignore certificate errors. But generally speaking, in order to see HTTP traffic, you must terminate the SSL session. And you can certainly re-encrypt to the backend server (a method usually called "SSL bridging").
- Rahul_Yadav_278
Nimbostratus
I have a question for clientssl profile we have used the certificate which is on servers but which certificate we will use for serverssl profile
- Kevin_Stewart
Employee
Rahul, see my 15-Feb-2016 response above. You usually don't need to configure any certs in the servers profile. These would be client certs to the internal application, which shouldn't need to authenticate the client. You can usually use the default servers profile if you need to re-encrypt to the application servers.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com