Forum Discussion
Martin_Smith_58
Nimbostratus
Oct 19, 2012Regular SSL/TLS for user connections to the LTM, with SNI support from LTM to the real webservers?
Hi there --
We have a client base that we truly can't force to support TLS SNI for HTTP traffic. However, we'd like to limit the number of IPs we put on our backend webservers. I'm wondering if ...
Kevin_Stewart
Employee
Nov 07, 2012SSL always makes the mass-virtual hosting part challenging, by virtue of the protocols. And one could argue that hardware-based SSL offload is a HUGE scalability win if your security policy will allow it.
That said, did you look at the iRule I posted above? It allows you to do SNI on the server side by injecting the name into the TLS extension of the server side CLIENTHELLO message.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects