Forum Discussion
Redirect traffic to one VS to another
It's definitely going to be difficult to inject any application layer logic without decrypted access to it. You could:
-
Create a NAT on the BIG-IP - more or less the same approach as your iptables idea, but within TMOS.
-
Create a layer virtual server - 443 destination port, 443 destination pool, no SSL offload. This, in my opinion, is better than the first approach because you can at least load balance the back end service and apply health monitors.
Both of these approaches assume you can route to the other service from the BIG-IP and you're okay making this the path to access this service.
All that said, please also consider what you gain when you offload SSL at this default-deny security appliance, and what you lose when you don't. In many cases, the strict interpretation and enforcement of "end-to-end" SSL is overcome by the benefits of offloading that client side SSL to a secure proxy.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com