For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Spidey_29396's avatar
Spidey_29396
Icon for Nimbostratus rankNimbostratus
Oct 19, 2015

Cookie persistence not working on SSL-reencryption

Hi All,

 

I'm having problem with cookie persistence.Currently we have this settings

 

ClientF5Server

 

Basically, we have client SSL profile and Server SSL profile. Both have certificate and key and the site is accessible. The problem is, i think cookie persistence is not working. My default is Cookie and fallback is Source persistence. I can see records of source persistence that leads to my suspicion that Cookie is not working.

 

Thanks! Ferdz

 

5 Replies

  • What is the current persistent ? Cookie right? And why and how do you think the cookie is not working, can you tell in more detail?

     

  • Hi Root44,

     

    Because the fallback persistence have records so i'm assuming that when the default persistence fails, the fallback will takeover.

     

    Thanks! Ferdz

     

  • Hi Root44,

     

    Because the fallback persistence have records so i'm assuming that when the default persistence fails, the fallback will takeover.

     

    Thanks! Ferdz

     

    • Root44_196087's avatar
      Root44_196087
      Icon for Nimbostratus rankNimbostratus
      I am not aware about fallback persistence but yes, if it is there then it will store the records i.e. when a connection is established from particular user, the IP address will be stored and whenever he/she will try establish again he will be directed to that particular node directly.
  • If I may clarify, the presence of source address persistence information is not indicative of anything "broken". In fact it makes sense if you think about it. You want to do cookie persistence and use source address as a fallback if the cookie doesn't appear in the client's request. But if there's no persistence information stored if/when the cookie doesn't come, then it's not going to help you. By enabling a fallback persistence mechanism in the VIP, the F5 will automatically start capturing affinity information, whether it's ever used or not.