For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

puru_73937's avatar
puru_73937
Icon for Nimbostratus rankNimbostratus
Oct 07, 2015

Need to configure Https VIP without ssl offloading in F5

i have configured the virtual server for https traffic but without ssl offloading in the F5. ssl offloading done on application server end. I have configured but is it not working showing page cannot displayed. if select default clientssl and serverssl in the ssl profile side then i am getting forbidden access on the denied.

 

8 Replies

  • Aee you sending to the correct port on the server?

     

    Do you have an https monitor on the pool? Is the pool up?

     

    • puru_73937's avatar
      puru_73937
      Icon for Nimbostratus rankNimbostratus
      Yes pool is up and i am able to telnet the port 443 only if i am not select ssl server/client profile then i am getting page cannot displayed. if i select default client server ssl profile then i am getting forbidden access denied.
  • Yes pool is up and i am able to telnet the port 443 only if i am not select ssl server/client profile then i am getting page cannot displayed. if i select default client server ssl profile then i am getting forbidden access denied.

     

  • Forbidden Access denied says to me that you are getting a 403 (as in a valid HTTP response even though an error) - will leave it to you work out why 403 being returned.

     

    Can you post your vs configuration (without the cleint/serverssl profiles)?

     

  • can you make sure your ip-protocol is set to tcp and the profile is tcp

     

    configurations of the pools/vs will help.

     

  • What you're describing is generally called "SSL tunneling", where the client and server negotiate SSL directly and the load balancer only handles layer 4 (TCP) traffic. The configuration for this is pretty straight forward. You need a VIP with a pool. Done. Because you're not managing SSL (layer 6) traffic, you can't have any application layer profiles either (as in no HTTP profile and/or cookie persistence). The 443 traffic enters the VIP and is blindly load balanced to the 443 pool members. Your best (and really only) option for load balancing persistence is source address.

     

  • @ Kevin Stewart

     

    ( The 443 traffic enters the VIP and is blindly load balanced to the 443 pool members. Your best (and really only) option for load balancing persistence is source address. )

     

    Can't we use SSL persistence in this scenario ?

     

    • Kevin_Stewart's avatar
      Kevin_Stewart
      Icon for Employee rankEmployee

      It's generally best practice to renegotiate SSL often, if for no other reason than to freshen the keys. Browsers and web servers will renegotiate periodically, making SSL persistence unusable. There are some very rare non-browser communications that don't renegotiate and can use SSL persistence, but again very rare.