Forum Discussion
Proxy SSL configured as per manual, connection reset occours
Do you have the "ProxySSL Passthrough" option enabled?
The first thing I'd do is run an ssldump capture on the client side of the F5 (client to F5).
ssldump -AdNn -i 0.0 port 443 and host [IP of VIP]
This will let you watch the SSL handshake and see where an error might be happening. For example, if the client doesn't send an RSA cipher in its ClientHello cipher list and you have the F5's client SSL profile to only accept RSA ciphers, the server (F5) will immediately send an alert and reset. If you have the Proxy Passthrough option enabled and everything starts working, that's usually a good indication that at least one side of the communication is not able to do RSA key exchanges, which is absolutely required for ProxySSL to work.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com