Forum Discussion
How SSL client connections diverted to the servers as HTTP (clear text) or HTTPS (SSL) according to the URI
Hi
I know two basic modes for dealing HTTPS/SSL incoming client connections:
-
BIG-IP ends the SSL connection and send requests to the targer servers in "clear text" (HTTP).
-
BIG-IP is configured as passthrough. BIG-IP does not decrypt the SSL connection and SSL stream reach the target server. Target server has to encrypt/decrypt the SSL connnection stream.
Is there any way (I mean an iRule) to select mode 1 or mode 2 according to the URI?
I guess there is no one -- unless BIG-IP ends client-side SSL and create a server-side SSL connection BUT then that will not be a genuine passtrough mode.
Thanx in advance
1 Reply
- nathe
Cirrocumulus
Damián,
As SSL transactions happens prior to HTTP then I would guess not.
In regards point 2 there is a (relatively) new feature called Proxy SSL which doesn't terminate traffic on the LTM, so is passthrough, but does then have visibility of the encryption key so it can inspect the traffic too i.e. where you might need to offload traffic to ASM.
Rgds
N
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com