Forum Discussion
Joel_106642
Nimbostratus
Sep 30, 2008SSL LTM 9.3 can't get it to work
We tried to cut over to a new pair of 6400s which have an ASM module. The F5 uses a virtual network server for all traffic to the inside vlan that doesn't require loadbalancing. All of the VIPs work...
hoolio
Cirrostratus
Oct 01, 2008For upgrading I say 'consider' 9.4.5HF2. 9.3.1 is more stable as it's a maintenance release. 9.4.5 will have much better performance for ASM and the new ASM policy format--but it's less stable. You would get better out of the box security with the ASM attack signatures in 9.4.5. And you'd avoid having to build a 9.3.x format policy and have to migrate that to the new 9.4.5 format. So I wouldn't say it's an automatic decision.
The SNAT iRule should work find as long as you have a floating self IP address on the VLAN that the traffic to the pool would go through. You could simplify the configuration for your basic initial test by just applying SNAT automap on the VIP for all connections. Once that's working, you can add the iRule.
Was the HTTP VIP whcih was working referencing pool members on the same subnet as the HTTPS VIPs' pool? There shouldn't be any difference in configuration between a standard TCP VIP defined on port 80 versus one defined on port 443. So if the port 80 VIP was working correctly, just copy that config and use it for the port 443 VIP. Once that's working you can add the more complex objects like client and server SSL, the SNAT iRule, an HTTP profile and eventually an HTTP class with App Security enabled.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects