Forum Discussion
Tan_95038
Nimbostratus
Oct 09, 2013irule to select different SSL profiles based on the Client IP address
Hi
wondering if anyone can help , I got requirement to enable client authentication on one of the URL, But only apply to one of the client , the rest are still keep using existing profile.
so i will ...
Tim_Enos_126618
Nimbostratus
Oct 09, 2013Yes, which SSL profile is used is determined by the iRule. You don't need to configure a default one, though it doesn't harm anything if you do.
For what it's worth, I'm using such an iRule for a purpose similar to yours:
when CLIENT_ACCEPTED { if { [class match [IP::client_addr] equals "private_net"] } { SSL::profile A } else { SSL::profile B } }
leira_6079
Nimbostratus
Aug 12, 2015I realized this was an old post. The profile set in the CLIENT_ACCEPTED event occurred before ssl negotiation happen. I wonder why do you need SSL:renegotiate in the subsequent HTTP_REQUEST event.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects