Forum Discussion
redirection 80 to 443 and http to https without creating pools and virtuals
Well, not a redirect, but implementing "HTTP Strict Transport Security" will accomplish a similar result.
It is supported out-of-box since v12.0.0. From the Release Notes of that version:
HTTP Strict Transport Security (HSTS) functionality
In this release, an HTTP profile provides HTTP Strict Transport Security (HSTS) settings that apply HSTS security functionality. This functionality requires all non-secure HTTP traffic to use secure HTTPS connections for both a domain (and optionally its subdomains) and persisting client HSTS security functionality, for a specified period.
Or it can be implemented via an irule. See: https://devcentral.f5.com/articles/implementing-http-strict-transport-security-in-irules .
Anyhow, this will at least draw your attention to the security issues of an HTTP->HTTPS redirect so frequently requested.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com