Forum Discussion
Question on configuring SNI clientSSL Profile
- Jan 30, 2025
As long as you are on at least version 11.6.0, you do not need to specify a Server Name for any of the profiles (and I would recommend not specifying it).
Simply add all 3 x Client SSL profiles to the virtual server and mark one of them as Default SSL Profile for SNI like you said and you're set. The F5 BIG-IP will automatically read the SAN names on all the SSL certificates to find a match. If it does not find a match, then it will use the default SSL profile.
As long as you are on at least version 11.6.0, you do not need to specify a Server Name for any of the profiles (and I would recommend not specifying it).
Simply add all 3 x Client SSL profiles to the virtual server and mark one of them as Default SSL Profile for SNI like you said and you're set. The F5 BIG-IP will automatically read the SAN names on all the SSL certificates to find a match. If it does not find a match, then it will use the default SSL profile.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com