Forum Discussion
SSL offloading on a non-ssl VS
I'd like to set up a virtual server which listens on non-ssl port but the pool members needs to be ssl. Here's the flow, F5 Virtual Server (80) -- Pool (443) and the response should be sent back to 80 to Virtual server. How should I achieve this ? iRule or through SSL profiles ? enabling server ssl and client ssl to empty? will it do it ?
2 Replies
- Stanislas_Piro2
Cumulonimbus
Hi,
The answer is in the question!!!
If the virtual server have a serverssl profile without clientssl, it will have the expected behavior!
Hi Susheel,
LTM operates always in a full-proxy mode, where the client side connection and server side connection is completely separated.
You can configure the client side connection on whatever port you need (via VS setting) and with or without SSL encryption (via Client-side SSL Profile settings) and combine it with a server side connections on whatever port you need (via Pool Members) with or without SSL encryption (via Server-side SSL Profile). Sky is just the limit in this case...
You will only need to deploy an iRule/LTM Policy if your scenario requires to selectively switch between Server-Side-SSL or Server-Side-Plaintext on the same VS.
Cheers, Kai
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com