Forum Discussion
jpotts_106582
Nimbostratus
Feb 22, 2008Exchnage 2007 OWA/ActiveSync SSL Offload
We are looking at using our LSM to offload SSL for our Exchange environment. Currently we have a single cert that points to the Exchange CAS server for OWA, ActiveSync and Outlook Anywhere. Looking at the configuration guide for Exchange 2007 there are different persistence profiles for these different services.
My question is, is there a way for the BigIP to get all of these services to work using a single external cert to offload SSL and then connect to a single CAS server?
Thanks,
Jamie
7 Replies
- Chris_17947
Nimbostratus
Hello,
Let me see if I can provide some more clarification on what we are asking. Our current deployment of the exc 2007 CAS services are all tied to a single SSL cert, and thus a single FQDN. When setting up ssl offloading on our big ip's for OWA, OutlookAnywhere, and ActiveSync we found that each of these services require individual customizations (cookies, and persistence profiles etc..) requiring three seperate virtual servers be configured. From the looks of it we can t perform ssl offloading with out modifying FQDN's and purchasing additional certificates or a cert capable of subject alternative names.
Is there a way to run all three of these externally accessed sites off of one configured virtual server on the big ip's, allowing us to avoid the extra cost of new certificates?
Thanks in advance for any help provided.
Chris - Ryan_Korock_46Historic F5 AccountJamie, Chris,
Have you looked into using UCC certs? They allow for multiple hostnames to be used for this exact reason.
Plus, the BIG-IP supports the use of them for termination purposes.
Let me know if you need more details. r.korock@f5.com
Ryan - Leslie_South_55
Nimbostratus
Would the Alternative Name certs work as well?
-L - Stevie_112040
Nimbostratus
Hi!
I would like to buy and use UCC certs with my LTM (exchange environment). What do I need to do?
Steve - Bob_James_87652
Nimbostratus
Even with the Subject Alternative names you need a different persistence profile for RPC versus https:
when HTTP_REQUEST {
if { [HTTP::header "User-Agent"] contains "MSRPC" } {
persist uie [HTTP::header "Authorization"] 3600 }
else {
persist cookie
}
} - Nick_T_68319
Nimbostratus
How can you generate Subject Alternative Names with the F5? - Ryan_Korock_46Historic F5 AccountNick, every CA is going to be different, but most of the time you can just generate the CSR from the BIG-IP with a single primary name. When you go to submit the CSR to your CA, request a SAN Cert, and they will prompt you to add any additional names at that point.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects