Forum Discussion
Is there TLS involved here? Is the internal VIP supposed be encrypted and have a client SSL profile? Is the external site encrypted?
Hi Kevin,
Yes, the external site is encrypted, as well as the connection to the internal VIP.
I have a certificate associated with the client SSL profile which matches the internal.com DNS name pointing to the VIP, as well as the server SSL profile set to use serverssl, which I think just leverages the external.com server's certificate when brokering the connection?
Thanks!
- Kevin_StewartOct 19, 2022Employee
Try taking off the client and server SSL profiles. A browser wil through an error because of the cert mismatch, so you'll probably want to test with Curl. If you can get to the site this way, then there's likely an issue in the server side SSL handshake.
If you still can't get to the site, check that traffic is leaving the BIG-IP to the intended destination. YOu can also try to Curl directly from the BIG-IP to see if the box can even get there.