Forum Discussion
Internal to external generic proxy possible?
I have setup internal to external proxies for single hostnames with the Big IP before but the setup is a little clunky. Mainly because you have to have a VIP for each hostname and when put in the hostname in the node or pool, it resolves the DNS for the hostname and adds the node in as a IP. If DNS resolution chhanges then the proxy breaks.
Is it possible, perhaps via iRule to do a DNS lookup in realtime on the pool member and then set the node to what DNS resolves?
What I would like to do is have a generic virtual server which could handle internal to external proxy for any hostname (not just a single hostname).
Why on earth would we do this you ask... right now we do it to handle some TLS1.0 to TLS1.2 connections for apps that can't yet talk in TLS1.2 but our end points have already forced TLS1.2 and we have no choice in that matter.
Maybe this iRule can help you out:
https://devcentral.f5.com/codeshare/http-forward-proxy-v32
I used a slightly modified version of this iRule for a customer to allow legacy servers with outdated cipher suites and/or TLS implementations to connect to the internet.
- Stanislas_Piro2
Cumulonimbus
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com