Forum Discussion
Ssl offloading
Your conclusions about the Clientside SSL profile are correct. I'm only adding that when you map a serverside SSL profile to your Virtual Server, F5 (re)encrypts the traffic flow, before sending the request to end-server. It's an extra layer of security indeed. In some business sectors and jurisdictions, regulatory requirements oblige customers to encrypt the entire traffic flow from end-server to end-customer. In such cases, you have no choice. In all other cases it's up to you. What do you value more - performance and ease of management, or additional security?
Your questions:
Also if we are using the ssl profiles ..we creatr virtual server on port 443 .what port should the web service be running ??http ??
If ssl server profile is used, can we use the pool members to be on port 443??
- If do not want to encrypt the traffic flow between BigIP and end-server, but do want to do so for the traffic between BigIP and end-customer, you can use port TCP 443 for your Virtual Server listener and port TCP 80 (or 8080, or any other standard non-SSL HTTP port) for your Pool Members.
- If you want SSL between BigIP and end-server as well as between BigIP and end-customer, you should use TCP 443 for Virtual Server listener and port 443 (or 8443, or any other standard SSL-enabled HTTP port) for your Pool Members.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com