Forum Discussion
Need to configure Https VIP without ssl offloading in F5
i have configured the virtual server for https traffic but without ssl offloading in the F5. ssl offloading done on application server end. I have configured but is it not working showing page cannot displayed. if select default clientssl and serverssl in the ssl profile side then i am getting forbidden access on the denied.
8 Replies
- IheartF5_45022
Nacreous
Aee you sending to the correct port on the server?
Do you have an https monitor on the pool? Is the pool up?
- puru_73937
Nimbostratus
Yes pool is up and i am able to telnet the port 443 only if i am not select ssl server/client profile then i am getting page cannot displayed. if i select default client server ssl profile then i am getting forbidden access denied.
- puru_73937
Nimbostratus
Yes pool is up and i am able to telnet the port 443 only if i am not select ssl server/client profile then i am getting page cannot displayed. if i select default client server ssl profile then i am getting forbidden access denied.
- IheartF5_45022
Nacreous
Forbidden Access denied says to me that you are getting a 403 (as in a valid HTTP response even though an error) - will leave it to you work out why 403 being returned.
Can you post your vs configuration (without the cleint/serverssl profiles)?
- ksanyal_118629
Nimbostratus
can you make sure your ip-protocol is set to tcp and the profile is tcp
configurations of the pools/vs will help.
- Kevin_Stewart
Employee
What you're describing is generally called "SSL tunneling", where the client and server negotiate SSL directly and the load balancer only handles layer 4 (TCP) traffic. The configuration for this is pretty straight forward. You need a VIP with a pool. Done. Because you're not managing SSL (layer 6) traffic, you can't have any application layer profiles either (as in no HTTP profile and/or cookie persistence). The 443 traffic enters the VIP and is blindly load balanced to the 443 pool members. Your best (and really only) option for load balancing persistence is source address.
- Sajan_Network_3
Nimbostratus
@ Kevin Stewart
( The 443 traffic enters the VIP and is blindly load balanced to the 443 pool members. Your best (and really only) option for load balancing persistence is source address. )
Can't we use SSL persistence in this scenario ?
- Kevin_Stewart
Employee
It's generally best practice to renegotiate SSL often, if for no other reason than to freshen the keys. Browsers and web servers will renegotiate periodically, making SSL persistence unusable. There are some very rare non-browser communications that don't renegotiate and can use SSL persistence, but again very rare.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
