Forum Discussion
Ray_Dodier_1102
Nimbostratus
Sep 03, 2010SSL connect time diffs between domains (VIPs)
I serve HTTPS content from two different domains and each domain name corresponds to a VIP. What I'm seeing is the SSL connect time from one domain is about twice that of the other domain.
Not sure if this matters, but the VIP corresponding to the domain with the faster SSL connect time is using an iRule filter to get to the static content pool. The VIP with the slower SSL time has no rule and just goes directly to a different static content pool. I tried making the slower one go through a rule instead of dir4ectly to the pool but saw no difference.
I'm not finding anything obvious as to why one domain (both are in the same subnet) is performing so differently than the other. My limited understanding of this is that the SSL time is strictly between the client's browser and the F5. If so, there should be no difference, but there is. Can anyone think of what might be causing this performance difference?
5 Replies
- Hamish
Cirrocumulus
Could be lots of things... What I'd suggest is you break it down and look at each portion of the connection individually. - Ray_Dodier_1102
Nimbostratus
So here's the deal. The VIP with the longer SSL time is not doing the SSL handshake correctly at least half the time. - Ray_Dodier_1102
Nimbostratus
More info on this -
- Ray_Dodier_1102
Nimbostratus
So is there anyone who knows why the F5 would alternate between 1 of 2 sessionIDs in the Server Hello response in the SSL handshake for every connection? I tried disabling one of the 2 servers in the static content pool in the event it was somehow using that to build the sessionID but I still get the same thing. - hoolio
Cirrostratus
Considering how you've isolated the performance issue to SSL session re-use, I'd suggest opening a case with F5 Support. They should be able to review your full config and binary tcpdumps to help you resolve the issue. We could give you hints and tips, but the support route would probably be a lot quicker as they'll be able to inspect the full data.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects