Forum Discussion
F5 Proxy termination
Hi, I have Entrust certificate that is installed on web Server and also import same certificate to F5 Reverse Proxy. my question is when internet traffic terminate at F5 proxy do i need to take special consideration to initiate again secure/encrypted communication between F5 proxy to web server, having a assumption during termination and re-initiate the new session will not change in source packet
URL -->F5 Reverse Proxy (Traffic terminate)--> new session initiate without changing source packet --> webserver (Same Certificate installed that was used by F5 Proxy)
thanks
- Raz_9876_111111
Nimbostratus
In other word i want end to end encryption
- Leonardo_Souza
Cirrocumulus
You need a clientssl profile with the certificate and private key, to handle the encryption between the client and the F5 device. Then you just need the default serverssl profile, so the traffic is sent encrypted from the F5 to the server.
Unless you are validating the client (in this case F5) when talking with the server, the default serverssl profile is ok.
It seems that you are looking to setup the LTM to proxy ssl. Check out this link: https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm-implementations-11-4-0/15.html
Be aware that ephemeral keys are not supported, the need for possible persistence and security considerations. Thanks!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com