Forum Discussion
strongarm_46960
Nimbostratus
Oct 05, 2010No server hello, no pool packets
when configured using port 80, everything works fine, as soon as I switch to SSL, pool side fails to send.
I am using automap. usedthe SSL profile on client and server side, From the tcpdump, my ssl connection reaches the virtual, however, when I sniffed the pool(443) nothing.
Somewhere after the virtual and the pool, packets are getting dumped, any ideas. Also, changing the cert to the default self signed, no server hello is not being sent out.
Openssl client test on the LTM to the virtual:443 and pool:433 presents both certs fine.
what Am I missing.
13 Replies
Sort By
- Chris_Miller
Altostratus
Can you telnet from LTM to server:443 and do an HTTP GET? - strongarm_46960
Nimbostratus
Posted By Chris Miller on 10/05/2010 09:10 AMmany thanks.
- Chris_Miller
Altostratus
Posted By strongarm on 10/05/2010 09:29 AMmany thanks.
- strongarm_46960
Nimbostratus
Like I said, the first part of the connection( to Virtual) works fine, I see the client & server cert being exchanged. Its the pool connection which shows no packets, nothing.Funny part is changing everything to port 80 works.
Could it be a Network firewall blocking packet to the SNAT address on port 443? but then why would i be able to receive the server cert (pool side).
thanks.
- Chris_Miller
Altostratus
Posted By strongarm on 10/05/2010 10:09 AMFunny part is changing everything to port 80 works.
Could it be a Network firewall blocking packet to the SNAT address on port 443? but then why would i be able to receive the server cert (pool side).
thanks.
- George_Watkins_Historic F5 AccountSounds like you've got just about everything covered in your original post, but I'll give it a shot.
- George_Watkins_Historic F5 AccountAlso make sure that you do indeed have a floating self-IP assigned to the egres VLAN and that your origin server has a route back.
- strongarm_46960
Nimbostratus
Thanks, I'll watch out for those silent drops, certainly appears to be a blocked snat 443 port through firewall. - George_Watkins_Historic F5 AccountAwesome strongarm, glad you found the smoking gun! :-)
- Chris_Miller
Altostratus
Posted By strongarm on 10/05/2010 11:18 AMGood deal...snat is a fun one. Health checks originate from the unit's self-ip while snat auto-map uses the floating IP. That can get a bit weird since your pool members might appear up since health check traffic gets through but real traffic can't.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects