Forum Discussion
Shawn_85639
Nimbostratus
Apr 14, 2010Internet Explorer cannot display the webpage
I am trying to set up a simple Virtual Server using SSL between the client and the F5. When I set the service port on the Virtual Server to 443 and set the SSL profile (Client) to our use our cert we get a Internet Explorer cannot display the webpage. But if we refresh the page everything works as expected. Re-start IE or firefox and we get the error once again. What's going on here ?
8 Replies
- Cspillane_18296
Nimbostratus
Hello Shawn,
I've not come across this issue myself before but I would be tempted to run an ssl dump to see what's happening, details can be found here:
https://support.f5.com/kb/en-us/solutions/public/10000/200/sol10209.html
Presumably the issue only occurs using your own certificate, and the default cert doesn't exhibit the same behaviour? - Shawn_85639
Nimbostratus
With more testing the issue occurs when I specify port 443 on the on the virtual server and not when I use a cert. - Cspillane_18296
Nimbostratus
If the ssldump doesn't help, are you able to post up the VS configuration here please? Are there any iRules that might be impacting the connection? - Shawn_85639
Nimbostratus
ssldump didn't help much. Communications are all successful. There are no irules applied to this virtual server. The VS is default. Host with a 10.1.201.102 address service port set to 443 config set to standard no ssl profile. SNAT pool set to auto map. Resources set to a pool with one server set to answer on :7150 I have also set up a tinyweb server and replicated the VS settings and I do not get the error message. It points to a server issue but the communication works fine when I change the VS on the F5 to communicate on any other port. - Shawn_85639
Nimbostratus
ssldump didn't help much. Communications are all successful. There are no irules applied to this virtual server. The VS is default. Host with a 10.1.201.102 address service port set to 443 config set to standard no ssl profile. SNAT pool set to auto map. Resources set to a pool with one server set to answer on :7150 I have also set up a tinyweb server and replicated the VS settings and I do not get the error message. It points to a server issue but the communication works fine when I change the VS on the F5 to communicate on any other port. - Cspillane_18296
Nimbostratus
Hello Shawn,
I'd definately expect a client ssl profile to be used (and a server ssl profile unless terminating the ssl connection on the BigIP).
Just out of interest, do you also get the issue if the VS listens on a different IP address (still using port 443)? - naladar_65658
Altostratus
Like Cspillane mentioned above, the most common setup I have used in this type of situation is:
Server: 10.1.201.102
Service Port: 443
Protocol: TCP
Protocol Profile Client: tcp
HTTP Profile: http
SSL Profile (Client): Here is where I would use the SSL Certficate made for the website/URL
SSL Profile (Server): serverssl
SNAT Pool: Auto Map
If you are using an IIS server in this type of setup, you would also need to export the SSL Cert and key off of the F5 BIG-IP, convert it to .pfx format using "OpenSSL" or something similar. Then import that into your IIS website under the Directory Security tab, Secure Communications Section. Just click on the "Server Certificate..." button and import the .pfx formatted certificate. If you have any issues with formatting to .pfx let me know and I can provide more instructions.
What kind of web server are you running and are you running multiple sites off of it?
Also, for future reference, this question might be better suited for the advanced desing and configuration forum since you are not having issues with an iRule really. - Chris_56952
Nimbostratus
If using Internet Information Server and it is not listening on a standard port, you could be seeing IIS issuing a courtesy redirect and responding with the port number that IIS is listening on, which causes the failure.
Are you using redirect rewrites within your HTTP profile?
Also, I'm interested in what firefox responds with because it provides better error messages (usually).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
