Forum Discussion
irule to a pool using SSL
What I am trying to achieve is to send traffic to a specific pool based on the uri. Which works fine on http, the issue I have is when I use the irule on https.
I have to assign an http profile to enable me to add an irule, when I add the standard http profile we have the site browses very slowly or gets connection time out. I am assuming I need a different setting in the profile or + ssl profile (server).
Does anyone have any info on what the settings should be in an http profile (to allow ssl to work) or pointers to it? (FYI - if I add the http profile with no irule it does not work - so it's not the irule).
thanks in advanced
- Kevin_Stewart
Employee
Does it actually browse very slowly and or sometimes time out, or does it just not work when you add the HTTP profile? There could be several things amiss here: - nastymatt_11986
Nimbostratus
Excellent info there.. working through it now... here is some more info if it helps:
wom-default-serverssl
(and no http profile) it works fine, add the http profile and it stops.
- nastymatt_11986
Nimbostratus
Think I am getting closer: - Kevin_Stewart
Employee
I'm not sure that applies. - nastymatt_11986
Nimbostratus
"So, how is your VIP configured with respect to SSL encryption/decryption?" - are you talking about client and server profiles? If so, I have tried a combination of all the standard ones and they do not seem to work. - nastymatt_11986
Nimbostratus
Thinking about it.. I'd need the cert on the f5 to be able to unencrypt. That's not on there... - Kevin_Stewart
Employee
Let's step back and reassess. - Kevin_Stewart
Employee
"I'd need the cert on the f5 to be able to unencrypt" - nastymatt_11986
Nimbostratus
Correct KS.. the BIG-IP is listening on 443 and forwards to 443. If I add client and server ssl profiles I get the trust error. The problem is these are public web sites being served so can not have trust issues :( - Kevin_Stewart
Employee
So to summarize then, if you don't SSL offload, you can't apply an HTTP profile or use this iRule. If you do SSL ofload, you'll need to get the certificate and key from each web server behind the BIG-IP to stop the trust errors.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com