Forum Discussion
hai1001_138479
Nimbostratus
Apr 21, 2014Getting client original source IP for SSL/TLS session terminated by the servers to perform authentication and authorization, not F5
Is it correct that if I use Proxy SSL feature for both client and server profiles in the virtual server, I will get the client original source IP for all SSL/TLS sessions handled by the back-end serv...
Kevin_Stewart
Employee
Apr 21, 2014Routing is independent of SSL, so any routing configuration would be the same regardless of how or if you applied SSL offload. So with SSL/TLS/ProxySSL removed from the equation, in order to get the client's IP address to the server, simply do not apply a SNAT profile. To get the server to respond to the client back through the F5, you would need to configure the server to use the F5's internal self-IP as its default gateway, or set a static route if you know all of the client subnets.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects