Forum Discussion
youssef1
Apr 11, 2019Cumulonimbus
Hi,
Did you check this post: https://devcentral.f5.com/questions/client-ssl-profiles-using-sni-not-able-to-use-the-subject-alternative-name
It explain how you can achieve your need.
Response from Kevin (F5): SNI doesn't really care about what's in the certificate, but rather what you've defined in the Server Name attribute of the client SSL profile. I haven't tried this, but thinking you could create a separate client SSL profile for each SAN name that isn't covered by the wildcard, using the same cert/key, and then apply all of those to the VIP.
Let me know if you need help