Forum Discussion
SSL Offload and re-encrypt traffic between Route Domains
SSL Offload and re-encrypt traffic between Route Domains
like use NGFW features (IPS & AV) with F5 LTM. Traffic flow will be External client --- > fw1 --- > LTM (RD -01) --- > fw2 ---- > LTM (RD -02) --- > pool member ( web server)
SSL offload needs to be done on LTM (RD -01) without any pool members. Server SSL need to be done on LTM (RD -02) to re-encrypt the traffic.
Could I please have some guidance to create an irule if that works?
1 Reply
- Kevin_Stewart
Employee
Sanjeewa, you don't really need route domains if this is all layer 3 traffic. You simply need to create separate VLANs and self-IP subnets between each FW.
- External client talks to FW1 on subnet1
- FW1 talks to LTM on subnet2
- LTM pools to FW2 on subnet3
- FW2 default routes back to TLM on subnet4
- LTM pools to web server on subnet5
Subnets 2 through 4 would all be internal, and as long as address translation is disabled, the destination IP could remain unchanged until you get to the LTM pool.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com