Forum Discussion

Blue_whale's avatar
Blue_whale
Icon for Cirrocumulus rankCirrocumulus
Jan 30, 2025
Solved

Question on configuring SNI clientSSL Profile

Hi Experts ,

 

I have a question on configuring the SNI SSL profile .Suppose say I have 3 different certificate and 3 SSL profile to be attached to the VIP to configure SNI . 

https://www.securesite1.com ClientSSL1 > Default SSL Profile for SNI

https://www.securesite2.com ClientSSL2

https://www.securesite3.com ClientSSL3

 

To enable SNI, we configure the Server Name and Default SSL Profile for SNI will be checked on an SSL profile of ClientSSL1, and then assign the profile to a virtual server. 

How about on other 2 SSL profiles ClientSSL2 & ClientSSL3 ? For other SSL profiles do I need to type the name for the HTTPS site in the Server Name box ? or it can be left blank ? 

 

 

  • As long as you are on at least version 11.6.0, you do not need to specify a Server Name for any of the profiles (and I would recommend not specifying it).

    Simply add all 3 x Client SSL profiles to the virtual server and mark one of them as Default SSL Profile for SNI like you said and you're set. The F5 BIG-IP will automatically read the SAN names on all the SSL certificates to find a match. If it does not find a match, then it will use the default SSL profile.

  • As long as you are on at least version 11.6.0, you do not need to specify a Server Name for any of the profiles (and I would recommend not specifying it).

    Simply add all 3 x Client SSL profiles to the virtual server and mark one of them as Default SSL Profile for SNI like you said and you're set. The F5 BIG-IP will automatically read the SAN names on all the SSL certificates to find a match. If it does not find a match, then it will use the default SSL profile.