Forum Discussion
Server Certificate Configuration..????
I am configuring complete encryption for my traffic as shown below. The url configured in the DNS is myaccess.com which loadbalance to server1.com:8443 and server2.com:8443.
client browser --> F5 LTM --> Servers
I am using client certificate to offload SSL on F5 and do i need a saparate server certficate for F5 to pool members? Is this certificate created using server hostnames or the VIP url?
I am bit confused now and can somebody help me with this?
Regards,
1 Reply
- afedden_1985
Cirrus
For end to end SSL, Your VIP would listen on port 443 and will need a HTTP profile and a SSL Profile (Client) profile with the ssl certificate and key for the VIP. To re-encrypt just add a SSL Profile (Server) called serverssl. This will re-encrypt the traffic sent to the pool members over port 8443 if you added the port to the pool members. The Servers will need to be HTTPs enabled and be listening on port 8443 and would need their own ssl certificates.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com