Forum Discussion
Policies to move HTTPS traffic
Good Afternoon Daniel,
I have followed your guide, and the tech doc. to create the VIP/Policy and SSl profiles. I added logging as well to the policy. I am getting log entries for this policy. I have compared pcaps from going through the VIP and going directly to the server. I have captured on both the client side and server side of each. (on the VIP captures) I see the Client hello - client side, client key exchange - server side and a cipher secs finish - client side.
On the client side capture there is a server hello - change cipher specs and
a change cipher specs finished
that is not present in the client to server capture (no LTM)
an HTTP get / http/1.1 with the full URI https://view.mycomp.org
the vip ACKs the change cipher specs
ACKs the Get
and sends a RST
On the server side capture I get a encryption alert 21 from the VIP.
I think I am making progress.
Any ideas for me on this?
Thank you,
John
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com