Forum Discussion
SSL issues with new setup
Interesting, I was told by our implementer that a "SSL Profile (Server)" was not required. I'm not quite sure what the proper way to setup the server ssl profile is? I'm assuming it would match-ish (yea, I'm making up words) the client side? So something like
ltm profile server-ssl Modified_serverssl {
app-service none
cert WildCard24
defaults-from serverssl
key WildCard24
log-ssl-c3d-events debug
log-ssl-client-authentication-events debug
log-ssl-forward-proxy-events debug
log-ssl-handshake-events debug
options { no-tlsv1.3 no-dtlsv1.2 }
}
I added in an SSL Profile (server) and the wireshark seems to indicate that I get a good connection.
If I go to https://bigip.domain.com I don't get a "site can't be reached" with "err_connection_reset" message, instead I get a "Not Found Http error 404" however if I go direct https://msnav01.domain.com I get the IIS welcome page so I'd expect if the BigIP were working correctly, if I go to https://bigip.domain.com I should be seeing the IIS welcome page.
irbk If you intend to reencrypt the traffic that the F5 decrypted and send it to 443 on the pool member you absolutely need an SSL server profile which can use the default profile of clientssl so that the F5 does SSL negotiation between it and the pool member just like the client did between itself and the F5. In regards to your 404 issue, this is most likely occurring because the page you are attempting to reach on 443 is not available. It seems like everything from this point forward is a server side issue rather than an F5 issue.
- irbkSep 28, 2023
Cirrus
Currently the BigIP only has 1 pool member, msnav01.domain.com (I've disabled the other one for testing). If I go direct https://msnav01.domain.com I get the IIS welcome page so I'd expect if the BigIP were working correctly, if I go to https://bigip.domain.com (which can only load balance to msnav01.domain.com) I should be seeing the IIS welcome page.
- PauliusSep 28, 2023
MVP
irbk To make sure I understand. The URL "https://msnav01.domain.com" points directly to the server and URL "https://bigip.domain.com" points to the F5 virtual server? If you are not seeing the IIS page when going to the bigip domain it's most likely that the server is not configured to respond to host "bigip.domain.com" but "msnav01.domain.com" which is why you are receiving the error. Try editing your hosts file to point "msnav01.domain.com" to the IP of the F5 virtual server and see if you are having the same issue. This still seems like a server issue because 404, unless otherwise configured, would only come from the server and not the F5. If you open of dev tools in your browser you can view the HTTP header field "Server" and it will most likely show some variation of "IIS" as the value rather than "BIGIP" which would imply you are making it to the server.
- irbkSep 28, 2023
Cirrus
Well, this whole thing may have been a red herring. paulj Yes, your understanding correctly. What I've just realized is that while going to https://msnav01.domain.com brings up an IIS welcome page going to https://<ip of msnav01> does NOT bring up an IIS welcome page <facepalm>. Just to test, I found another server that DID bring up a page when you went to https://<test ip> and created a new pool for the <test ip> and then adjusted my VS to use the new test IP pool and the thing worked. So it seems like this whole thing was a failed assumption. I should have verified that https://<ip of msnav01> also brought up an IIS welcome page.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com