For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

HDO_163232's avatar
HDO_163232
Icon for Nimbostratus rankNimbostratus
Jul 09, 2014

iRule redirect https without profile

Hello,

 

I was wondering if the following scenario is possible with an F5 BIGIP LTM: - Have several sites running on http and https (IIS - with SNI) - Create Pools for each port - Have 1 health check on port 80 - Redirect traffic to both pools with 1 iRule - without any certificates on the loadbalancer

 

Would this be possible as the F5 also supports SNI from 11.x+? Or are the certificates always required on the loadbalancer for forwarding based on hostname to work?

 

Thanks in advance! H

 

1 Reply

  • SNI on the LTM is a function of the SSL profile, so by virtue of that you have to terminate the SSL at the BIG-IP to be able to use the SNI functionality, and this requires the cert and private key.

     

    In lieu of that, you cannot perform any OSI layer 7 functions (ie. HTTP redirects) without being able to see the decrypted traffic.