For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Brian_H__Jones_'s avatar
Brian_H__Jones_
Icon for Nimbostratus rankNimbostratus
May 27, 2015

Is it possible to load balance TN3270 over SSL?

Our end-users wants to do the following:

 

End-User: IBM TN3270 Client using TCP Port 1023 (unencrypted) to the VIP F5: Standard TCP VIP using Port 1023 to take the Unencrypted traffic from the end-user and encrypt the traffic to the mainframe which would be setup as a node in the pool using 1024. Mainframe: IBM Mainframe with the Telnet server configured for SSL using TCP Port 1024.

 

The connectivity direct to the Mainframe using port 1024 works using a newer version of the TN3720 client.

 

We would like to know if it is possible to load-balance this traffic with the F5 so that the TN3720 client does not have to be redeployed for the SSL configuration for the new Mainframe that we are migrating to. We are assuming that we are going to have to do a server-side SSL profile to make this work, but so far, no luck.

 

Any feedback will be welcome.

 

1 Reply

  • We are assuming that we are going to have to do a server-side SSL profile to make this work, but so far, no luck.

    can you post the virtual server configuration?

     tmsh list ltm virtual (name)
    

    have you tried tcpdump/ssldump? what did you get?