Forum Discussion
Need help with SSL passthrough while using SNAT and an irule
For the BIG-IP to be able to do HTTP-commands such as HTTP::uri and HTTP::respond it will need the certificate as well, so Ryan's question is a valid one - is SSL passthrough a requirement?
What SSL passthrough (or SSL Proxy as the feature is called in the GUI) means is that the client is negotiating the SSL/TLS session with the server and the BIG-IP sits kind of like a "man-in-the-middle" and decrypts the traffic using the same key/certificate as the server. Problem with this is that there is a bunch of restrictions regarding the ciphers being used, and in my experience it's a hassle.
So unless your application absolutely requires the client to negotiate directly with the server I think SSL bridging is the preferred solution. That means that the client negotiates the SSL/TLS session with the BIG-IP and then the BIG-IP negotiates another SSL session with the server.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com