Forum Discussion
Need to configure Https VIP without ssl offloading in F5
@ Kevin Stewart
( The 443 traffic enters the VIP and is blindly load balanced to the 443 pool members. Your best (and really only) option for load balancing persistence is source address. )
Can't we use SSL persistence in this scenario ?
- Kevin_StewartJul 12, 2017
Employee
It's generally best practice to renegotiate SSL often, if for no other reason than to freshen the keys. Browsers and web servers will renegotiate periodically, making SSL persistence unusable. There are some very rare non-browser communications that don't renegotiate and can use SSL persistence, but again very rare.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
