Forum Discussion
SSL Offload and re-encrypt traffic between Route Domains
SSL Offload and re-encrypt traffic between Route Domains
like use NGFW features (IPS & AV) with F5 LTM. Traffic flow will be External client --- > fw1 --- > LTM (RD -01) --- > fw2 ---- > LTM (RD -02) --- > pool member ( web server)
SSL offload needs to be done on LTM (RD -01) without any pool members. Server SSL need to be done on LTM (RD -02) to re-encrypt the traffic.
Could I please have some guidance to create an irule if that works?
- Kevin_StewartEmployee
Sanjeewa, you don't really need route domains if this is all layer 3 traffic. You simply need to create separate VLANs and self-IP subnets between each FW.
- External client talks to FW1 on subnet1
- FW1 talks to LTM on subnet2
- LTM pools to FW2 on subnet3
- FW2 default routes back to TLM on subnet4
- LTM pools to web server on subnet5
Subnets 2 through 4 would all be internal, and as long as address translation is disabled, the destination IP could remain unchanged until you get to the LTM pool.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com