Forum Discussion
Load Balancing Web Proxy Servers
Hi all.
Our case is close to the one described by agvelegol, but our VS is a standad one.
We have placed one BIG-IP to balance the HTTP/HTTPS traffic between our workers and two HTTP/HTTPS SQUID proxies. The VS has no profile applied but one HTTP profile to pass the x-forwarded-for, and a Persistence Profile to ensure that the same client source address is served by the same proxy server due to a existent Kerberos dialog between client and proxy server for which the BIG-IP should be transparent.
The problem is that when a client try to connect to an HTTPS site:
- the CONNECT macro reaches the VS
- the VS forwards it to the chosen proxy server
- the proxy server asks back for authentication
- the F5 forwards back this authentication to the client
- in that moment the F5 launchs a RST packet to the server and to the client.
This behaviour is repeated several times until the connection is down.
This behaviour doesn't happen with HTTP traffic, and the authentication that the proxy asks to the client through the F5 is successful.
Are we missing some configuration in the VS? Must it be configured as an Explicit HTTP proxy applying the http-explicit profile? Must it be configured on the contrary, with an http-transparent profile?
I would appreciate any help. Thanks a lot.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com