Forum Discussion
Josh_41258
Jul 31, 2012Nimbostratus
Lync SSL Config
I'm using the newest deployment guide and iApp template for Lync 2010. I have a question regarding the "Front End Virtual Server" configuration in the iApp template. This section creates a VS on TCP/443 for the FE. The pool members are also 443. However, there are no SSL profiles assigned to the VS.
When I browse to the VS via HTTPS, I am presented the internal SSL certificate that IIS on the FE is using. Is this how the VS is supposed to be configured? Shouldn't it be using both client and server SSL profiles instead of just passing the encrypted data back to the FE servers?
Thanks,
Josh
- Josh_41258NimbostratusMike,
- mikeshimkus_111Historic F5 AccountIt does seem like a routing issue. The iApp wasn't designed with this kind of setup in mind, although it's a scenario we can investigate and possibly add into the iApp. I see no reason why you would need both external and internal reverse proxy VIPs when deploying on one BIG-IP (or HA pair); you could copy the iRule that secures access to the external reverse proxy VIP, then reconfigure the iApp and NOT deploy the external reverse proxy VIP. Change the destination port on the VIP from 4443 to 443, and add that iRule to the internal reverse proxy VIP to secure access and you should be OK.
- Josh_41258NimbostratusAh, ok.. sounds like a much simpler solution. I'm getting stuck in a redirect loop here, though.
- mikeshimkus_111Historic F5 AccountYou do need to edit the iRule to send requests for those URLs to the internal, rather than the external, reverse proxy pool. You would also need to remove the default pool assignment on the internal reverse proxy virtual server, since you want all traffic not allowed explicitly by the iRule to be dropped.
- Josh_41258NimbostratusMy apologies.. I had the wrong iRule assigned. Everything seems to be working fine now. I'll remove the default pool. I really appreciate all of your help.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects