Forum Discussion
How can I configure Server SSL Profiles to connect to different URLs on the same server?
- Jun 24, 2015
Hello,
We had the same issue we had a single vip which teminated SSL at the LTM level but had to make two backend SSL connections to an HA-Proxy server so HA-Proxy would need to see the SSL call to a specific cert name. As you mentioned we created two separate Server SSL profiles each with differetn SNI and set one profile as default. No matter what we did the LTM only used the default profile SNI and ignored the secondary Server Profile's SNI when making the ltm to backend server SSL connection. Even in packet caputure we can see that it was only using default server's SNI only (we are running LTM 11.5.1. HF8). So that lead us to believe even though you can assign multiple server profiles with differetn SNI names, the LTM only uses the profile set as the default SNI and ignores the other profiles.
Our fix to this was to create a second VIP, map to the same backend servers and assign each vip with its own SNI profile. This is not an ideal setup if you are calling multiple certs or if you can't used multiple vips. But it worked for us and we didn't bother opening a case with F5 as I think you can not use multi-SNI calls on server side SSL calls.
We are using the latest Chrome build (43) and also IE10 and verifying against SNI validation websites checks out OK. I need to clarify what is required/possible in terms of client ssl profiles and server ssl profiles e.g. if the server ssl profiles are SNI based, must the client ssl profiles be SNI based also? Can we use SAN based client ssl profiles at the 'front' end between user and BIG-IP but use SNI based server SSL profiles at the 'back' end between the BIG-IP and server? Should we just use the default serverssl profile? We have tried many combinations and none of which have worked. The best we have gotten is the partial success as described in the OP.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com