Forum Discussion
MW1
Cirrus
Mar 27, 2009HTTPS monitor (and curl on a LTM/GTM) fails to connect full
All,
apologies as I realise this may not be 100% F5 but I'm only getting the issue on F5 devices so was hoping someone would be friendly enough to point me in the right direction for troubleshooting. I'm trying to setup a simple HTTPS health monitor on a LTM which matches 'SEND' on a page. (quick background this is not a actual webserver but an app built on the openSSL packages and displays in a web browser without issue). As the monitor fails I tried using curl, from my curl on my windows box it works without issue (using curl -vk https://208.16.209.148 and its curl/7.19.4). However when trying curl from several LTM's at different location I just get:
* About to connect() to 208.16.209.148:443
* Connected to 208.16.209.148 (208.16.209.148) port 443
and then no more, it doesn't show a handshake on the SSL etc. If this was plain HTTP I'd run a packet sniffer but a its HTTPS I presume there is no point as I can't see inside the communication. Can anyone suggest a way to trouble shoot this further?
thanks in advance
Matt
- MW1
Cirrus
Just as an update I've tested curl from a fedora 10 box against the IP and that works without issue as well. - MW1
Cirrus
Further update I was dropping out of the curl session too early on the LTM/GTM's and it appears to be a SSL handshake issue as I get the following if I leave it at the connected msg (see below) for about 3-4 mins): - MW1
Cirrus
Just as an update it appears there was a slight difference between curl on windows/fedora and the one on the F5 and I had to force SSLv3 and it works. The same goes for the the openssl s_client. However forcing SSLv3 on the F5 monitor still fails. - dennypayne
Employee
LTM does have ssldump, so that might help in digging into the payload to see what's going on. Nothing else is jumping out at me so far though.. - hoolio
Cirrostratus
You might be able to get more detailed info by enabling debug on the monitoring daemon, bigd: - MW1
Cirrus
All - thanks for the replies. Heres how my ticket ended with F5 tech support regarding getting the HTTPS inbuilt monitor to work:
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects