For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Jinshu's avatar
Jinshu
Icon for Cirrus rankCirrus
Nov 05, 2015

Server Certificate Configuration..????

I am configuring complete encryption for my traffic as shown below. The url configured in the DNS is myaccess.com which loadbalance to server1.com:8443 and server2.com:8443.

 

client browser --> F5 LTM --> Servers

 

I am using client certificate to offload SSL on F5 and do i need a saparate server certficate for F5 to pool members? Is this certificate created using server hostnames or the VIP url?

 

I am bit confused now and can somebody help me with this?

 

Regards,

 

1 Reply

  • For end to end SSL, Your VIP would listen on port 443 and will need a HTTP profile and a SSL Profile (Client) profile with the ssl certificate and key for the VIP. To re-encrypt just add a SSL Profile (Server) called serverssl. This will re-encrypt the traffic sent to the pool members over port 8443 if you added the port to the pool members. The Servers will need to be HTTPs enabled and be listening on port 8443 and would need their own ssl certificates.