Forum Discussion
Thornid
Nimbostratus
Jul 28, 2020Help with iRule to enable SSL profile based on XFF Header
Hi all We have some apps on our F5s that will need to go behind the Silverline WAF (can't use ASM so this is our only option). Currently on the F5s we have an iRule which selects a particular clie...
Simon_Blakely
Employee
Aug 03, 2020You need to use SSL::renegotiate
As you say, you need to examine the X-Forwarded-For header, but that does not arrive until after TLS negotiation.
So you establish un-authenticated TLS, and then examine the XFF header, select the new TLS settings, and SSL::renegotiate
However, the actual endpoint from the client perspective will be Silverline, who will be terminating TLS. I don't really see how you can make this work in this context.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects