Forum Discussion
Http Redriect Loop
Hi,
I want to do redirect from HTTP to HTTPS. I have set iRule.
when HTTP_REQUEST { HTTP::redirect "https://[HTTP::host][HTTP::uri]" }
On firefox, it loop but on chrome it's working ok. iRule on http virtual server. Virtual server have http and https. Also i have cert ssl install on F5. Please advice.
Thanks.
27 Replies
- Pragathishakart
Nimbostratus
Can you clear cache and try what chrome returns for the request? In application side, do they have content on the default page or any redirection applied?
- Kevin_Stewart
Employee
On login page our client have set check session.
What does this mean?
Before this, our client don't have any problem. But after renew certificate, all problem come.
Okay, so assuming you don't have any iRules on the port 443 VIP, can you elaborate on the port 443 vip's config? What does the client SSL profile look like? Are you using APM or ASM?
- Zainal_Abidin_1
Nimbostratus
Here is from virtual server for port 443.
- Zainal_Abidin_1
Nimbostratus
What does mean: a. APM b. ASM
- nitass
Employee
have you ever used http analyzer such as httpfox? it may be useful to find what wrong is.
HttpFox
https://addons.mozilla.org/en-US/firefox/addon/httpfox/ - Zainal_Abidin_1
Nimbostratus
On Profiles service HTTP, i change ignore headers from cache control to none. Will update here.
- Kevin_Stewart
Employee
What does mean: a. APM b. ASM
I'd assume by your response that you're not using either. These are licensed modules that act on authentication and web security. So again, if you have NO iRules on the 44 VIP, then the next likely culprit is perhaps the SSL negotiation. I would also reset the HTTP profile to use the default parent profile for now. I don't thing caching has anything to do with this, but better to remove any doubt. I would recommend two things:
-
First is Nitass' suggestion to use a client side capture mechanism like HttpFox, Fiddler, or HTTPWatch. Compare the dialogs with the different browsers.
-
If that doesn't yield anything useful, I'd probably fire up an SSLDUMP on the LTM command line and watch both the SSL negotiation and the lower level (TCP) transactions. All of this trouble appears to have started after you updated the certificate, so it's a fair guess that you'll see something funky in the SSL negotiation with specific browsers.
-
- Zainal_Abidin_1
Nimbostratus
How to fireup ssldump?
- nitass
Employee
How to fireup ssldump?
sol10209: Overview of packet tracing with the ssldump utility
http://support.f5.com/kb/en-us/solutions/public/10000/200/sol10209.html - Zainal_Abidin_1
Nimbostratus
Can i use this command: ssldump -k /config/ssl/ssl.key/our-domain.key -i 1.1 port 443 -A -d
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com