Forum Discussion
OCSP outbound LB through F5 VS
I'm trying to solve a problem of ocsp reachability. My primary OCSP service is upstream through network transport outside of my control. We have replicated responders closerto the F5's location. I have a list of servers that have replicated the OCSP functionality. I'd like to use these servers in a pool using priority group activation for node selection: The closest resolver server being preferred, then our backup site, then the FQDN node associated with the ocsp service itself as a last resort. I can hit each responder using a host file edit with associated FQDN in the OCSP Auth config object - so I know the responders are working and reachable. I need to have the query hit an F5 VS for LB to my pool; and this is where things are breaking. I can't seem to get an OCSP query through a standard VS. I'm missing something...Any suggestions?
- Rico_368208
Nimbostratus
Eric,
It is a bit hard to determine the exact issue just from you statement alone, but here are a few troubleshooting steps I would take.
- eric_haupt1
Nimbostratus
Nope - checked all of that.
- eric_haupt1
Nimbostratus
Ahhh... I found it. It's trying to use an egress point when LB'd that is not permitted through our firewall. I need to add another float IP for my second traffic group.
- Rico
Cirrus
Eric,
It is a bit hard to determine the exact issue just from you statement alone, but here are a few troubleshooting steps I would take.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com