Forum Discussion
Lance_53368
Nimbostratus
May 04, 2009Preserve Client IP address through HTTPS Virtua Server
Hello,
I have a pair of Microsoft web servers that were being load balanced with Microsoft NLB. Since I have moved them over to BigIP (LTM 3600 v.9.4.6), I have not been able to view client IP addresses in the web logs.
I have been able to get source IP addresses on http servers with using the X_Forwarded_For option in the http profile, but I have not been able to find any documentation on performing a simiilar funciton with ssl.
Has anyone done this?
Thanks,
Lance
2 Replies
- hoolio
Cirrostratus
Hi Lance,
If you are decrypting the SSL on LTM you can still insert the XFF header for HTTPS. If you're not decrypting the SSL, you won't be able to inspect or modify the HTTP headers or data. You could either decrypt the client SSL and re-encrypt it (if the LTM to application connection requires SSL), change the default gateway on the servers to the LTM self IP address and remove the SNAT configuration, or not get the original client IP address for HTTPS VIPs.
Aaron - Lance_53368
Nimbostratus
Thanks Aaron,
We opted to use the LTM floating IP as the default gateway for the web servers. That pretty much killed our ability to access the website from inside the firewalls, but we are able to access it from public addresses. We probably just need to configure a NAT or route on the firewall to take care of it.
Thanks again for the quick response.
Lance
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
