Forum Discussion
SSL offload to IPS
- Michael_YatesNimbostratusYou might want to investigate utilizing Clone Pools to see if it will do what you are needing.
- HamishCirrocumulusAgreed. Cloning the traffic is going to be far lighter on the systems than not.
- Steve_Brown_882Historic F5 AccountAnother interesting option I have seen tested to solve this issue actually involves using 2 different route domains on the LTM. Basically there is a front side route domain and a back side route domain with the IPS in the middle processing traffic transparently.
- Chris_MillerAltostratusEasiest way:
when HTTP_REQUEST { virtual virtual2 }
- Colin_Walker_12Historic F5 AccountNice tip Chris, I like it.
- hooleylistCirrostratus
Any idea if route domains are required? It seems like Chris's example with a VS targeting VS would work fine.
Thanks, Aaron
- Jacob_39432Nimbostratus
The problem with clone pools is that they require the IPS to actually be targeted in some way with an IP and MAC address. Many inline IPS deployments are completely transparent and there's nothing to target at L2/3. You're doing SSL offload to a ghost. This leads to the config mentioned by Steve which I have had the unfornuate experience of dealing with at length. It works but is a very complex setup. RD's are required b/c you'r processing the same traffic 2x targeting the same L2/L3 address space.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com