Forum Discussion
Persistence session
Hi all ,
I am new in the F5 administration, I share my configuration here, I hope someone can help me, I have configured a VS as standard, with a persistence session (JSESSION), via an iRule, however the certificate is carried by the backend server, my question could the F5 describe the content of the traffic, in order to redirect to the target server and take advantage of the session persistence required by the application ?
Thanks ;
you are welcome.
Here is an article on JSESSIONID persistence, in case you need it :
https://support.f5.com/csp/article/K7392If the cert is on the server that means your vip can not decrypt the traffic and it will not be able to read/see the cookie. To be able to use this persistence type your vip will need to have a cert and terminate the ssl session.
- Poseidon1974Cirrostratus
HI,
Thanks for you reply , I also had this doubt, but I wanted to have confirmation , so in addition to the certificate configured on the server, I must also install another one on the F5, or will a single certificate on the VIP F5 suffice?
Regards, Usually, it is enough to have 1 cert on the VIP. This way the traffic between the client and the VIP is secured.
But if you want you can have a cert on the server. This way also the traffic between the F5 device and the server is secured. There are scenarios where this is needed. There are security teams that ask that all traffic is secured (encrypted.)
- Poseidon1974Cirrostratus
Really thanks !
- Poseidon1974Cirrostratus
Hi ,
Thanks for your reply , just to confirm , in this kind of configuration , which profile we should configure :
- http_XFF
or
- http_XFF_HSTS
Thanks,
Hi,
Just for a little clarity if it helps, if you want to add the xff header to your http header.
Then this is set in the http profile.
its just a tick box you need to enable, either in the base profile but even better would be to make a new on with the base http profile as the parent and then add the xff header to that.Also you meantion certificates on the back end.
So, you can have the cert from the server also on your f5 at the front end dependant on your use case.
But you can also have it encrypted on the front end "client ssl" and have no cert on the back end server.
This would then make the flow from the f5 to the backend server unencrypted.
Which is fine, but you may need to talk to your security or architectual teams just to make sure they are happy with that. It will all depend on your security/risk posture and the network design.- Poseidon1974Cirrostratus
Hi ,
Thank you for this detailed answer, however my need is to know, how to make session persistence work, obviously as long as the certificate is on the server and not on the F5, it will not work. because the traffic will not be decrypted by the F5. you tell me, i can export the certificate currently configured on the server to the F5? how ?
Thanks,
Any HTTP profile should be ok
- Poseidon1974Cirrostratus
Thanks !!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com