Forum Discussion
John_Krum
Cirrus
Jul 07, 2021Policies to move HTTPS traffic
I am trying to share a 443 NAT on a firewall sending traffic to the LTM. Once it gets to the F5 I want formview.xxx.org to go to pool-Forms and WEBview.xxx.org to go to pool-WEB. Is that possible wit...
John_Krum
Cirrus
Jul 07, 2021I have looked at the first reference link earlier as well. Here is more detail regarding what I am trying to accomplish.
I have a outside firewall NAT for incoming 443 traffic on 96.103.236.222 that forwards that traffic to a LTM VIP 192.168.5.5 listening on 443.
I am trying to have sites
Viewforms.mycompany.org
And
Employee.mycompany.org
(I am also thinking it might be better to do
Mycompany.web.org/viewforms
And
Mycompany.web.org/employees
But the first one is preferred)
The VIP is basic.
HTTP profile is HTTP – I have to select a http or a http-connect profile (this is where I am not sure why I require an http profile, it makes me think that the server connection is http)
Automap
Resources
I don’t have a default pool selected (I did to verify I get the login page prior to adding a policy)
Policy is DMZ-Cop
DMZ-Cop is
Match
HTTP Host -> host -> is -> any of -> Viewforms.mycompany.org or viewforms -> at request time
Do the following
Forward traffic -> to pool -> viewforms-pool
When I https to the page Viewforms.mycompany.org I do not see any policy statistics, invoked or succeeded.
I haven’t tried adding any info for the second site.
Once I change the VIP config http profile (client) to http – I no longer connect to the login page. I do see TCP handshake, Client Hello, and an ACK to that. 1.5 seconds later a FIN from my side.
Thanks
John Krumenacher
John_Krum
Cirrus
Jul 15, 2021Daniel,
HEY HEY, I figured it out. I missed something so blatant I am too embarrassed to post it... Just kidding. When I added logging to do the following when traffic is matched. I never added back in the forward traffic to the pool. No kidding.
Thanks again for all your help.
John
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects