Forum Discussion
SSL cert 128 in with 256 out, F5 middleman
Is it possible to use the BigIP LTM to accept an SSL 128 connection in and to then make an SSL 256 connection out? We have an Internal app that only supports 128 at the moment connecting to a customer that only supports a 256 connection.
Thank you,
3 Replies
Yes this is possible. You just need to have both a client ssl and a server ssl profile to handle the ssl connections in both directions. Depending on your F5 version and your server supported alogrithms you may either use a default server ssl profile or customize a new one to support 'weakest' algorithms.
- Frank_Catapano_
Nimbostratus
Amine, So would my internal app connect to a VIP on the LTM using a 128-client cert and a 256-server cert?
Thanks,
Short answer is Yes.
F5 is acting as a full proxy device. This means that on each side, client-side and server-side, there is a separate connection. One of the multiple advantages of such architectures is that you can customize each of the two connections separately to match your specific needs. In your case a 256 bit key-size in one side and 128 bit in the other.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com