Forum Discussion
SSL client to f5 and f5 to websever
If I may add a few thoughts:
-
It doesn't appear that you have a server SSL profile applied to the VIP. In order to perform this "SSL bridging", you need a client SSL profile to first terminate the client side SSL, and then a server SSL profile to re-encrypt to the web server.
-
If it's still not working, I would FIRST look at where it's failing. Because you're dealing with a full proxy here, if you TCPDUMP on either interfaces (client side or server side) you should see where the traffic is failing. For example, if client side SSL is failing, you shouldn't see traffic on the server side.
-
Once you've determined where the problem is, you can then start looking at why it's failing. For this you can use a tool like SSLDUMP. It will generally, and not always intuitively, show you what's going on inside the SSL handshake, and will (sometimes) point right to the problem.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com