Forum Discussion
iRule to redirect from Exchange CAS iApp to SSL Passthrough virtual server
Curious to know if anyone has configured anything similar to this...
Basically we have configured the Exchange iApp template for CAS, for OWA, Autodiscover, ActiveSync etc. The associated VS is accessible via 'mail.organisation.com'
I've setup a separate ActiveSync virtual directory with a different hostname 'activesync.organisation.com'. It is configured for SSL passthrough, for the use of Client Certificate authentication (doesn't use password auth at all).
I'd like to configure activesync.organisation.com to resolve to the same public IP address as mail.organisation.com, but have an iRule which redirects the requests for 'activesync' to the SSL passthrough VIP.
Is it possible to perform this redirection without terminating the SSL connection?
1 Reply
- mikeshimkus_111Historic F5 Account
You may be able to do it by checking the server name extension in the request and placing your passthrough VIP in a separate pool to receive traffic for activesync.organisation.com. Check out the iRule from Arie here:
https://devcentral.f5.com/questions/match-ssl-sni-and-redirect-ssl-traffic-without-ssl-termination
Your AS clients would need to support SNI.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com