Forum Discussion
Luca_55898
Aug 01, 2011Nimbostratus
LTM SSL VIP Forward to node on port 81
Hi,
I have a VIP which is used for HTTPS access to a website.
I have applied the SSL cert and selected the cert in the SSL Client profile. All that looks to be working fine.
The pool that is assigned to the VIP just has one pool member and is added to the pool on port 81. The F5 forwards traffic to the server on port 81. This is needed because the server hosts multiple sites and the web developers use different ports to differentiate between the sites.
So the website starts with a logon screen, after someone puts in the credentials the page sits there for a minute, then just times out. The error is "Internet Explorer cannot display the webpage"
This only happens with the VIP is configured to listen on HTTPS and the SSL cert is in use.
If i configure the VIP to use HTTP then the users are authenticated and the page loads..
The web server actually queries another server for authentication, i can see all this traffic on our firewalls, and as i said this works when using HTTP only
So what am i doing wrong with the HTTPS VIP?
Are you able to use HTTPS and then forward traffic to the pool on a different port?
Do i need any other configs to get this working with SSL?
Port translation is enabled and is set to preserve the source port... not sure if that is relevent or not. I have mucked around with a few different settings but no luck.
thanks.
- natheCirrocumulusLuca
- Luca_55898NimbostratusHi Nathan,
- natheCirrocumulusLuca
- Luca_55898NimbostratusThere is a huge difference in the output between HTTP and HTTPS, when i do tcpdump on the HTTP connection the screen fills up instantly with heaps of data.
- Luca_55898NimbostratusLogs on the F5 show this error
- Anthony_GraberEmployeeLuca, you may want to use Fiddler or Firebug to see what's going on as well. You could try assigning an http profile with redirect rewrite enabled.
- Luca_55898NimbostratusYep that sorted it.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects