Forum Discussion
faizan123_23330
Nimbostratus
Sep 05, 2016SSL mutual authentication against the pool
we have configured a HTTPS virtual server on the f5 and we add a proxy pass(i-rule) and client side SSL certificate against that server.
in the i rule we have configured
when HTTP_REQUE...
Kevin_Stewart
Employee
Sep 05, 2016The issue here is that you cannot make a layer 6 (SSL) decision based on layer 7 (HTTP) information, simply because you don't have the layer 7 information until you've already made the layer 6 decision. At best you can make a decision based on layer 3 and 4 information (IPs and port) and potentially even layer 6 information (SNI).
You could simply force requests to a specific URI to redirect to another VIP that does mutual auth.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects