Forum Discussion
Sly_85819
Nimbostratus
Oct 13, 2009SSL pass-through configuration
Can someone tell me how to I configure SSL pass-through for Standard VS? Basically we dont want to have SSL offloading on LTM and the server should have SSL cert. I have used 2 options suggested by F5 support, 1) Configure serverssl profile as Server SSL Profile and 2) Configure none for Client and Server profile settings. The first option worked only once for us and then never worked for any other VS. The second option didnt work either.
The only way it worked is with Performance L4 type VS. I am wondering if anyone has successfully configured ssl pass-through with Standard VS.
- hoolio
Cirrostratus
If you don't want to configure SSL decryption on LTM, a Performance Layer4 VIP with a FastL4 profile should work. If you do want to decrypt the client SSL and re-encrypt the server side connection, you can use a standard VIP with a client and server SSL profile. The advantage to the latter option is that you can inspect and modify the HTTP. This includes using cookie persistence. The downside is that it's extra load on the servers and LTM as both need to decrypt the SSL. - Sly_85819
Nimbostratus
So far I worked on SSL pass-thru apps which didn't need HTTP inspection and I configured Performance L4 VIP's. I just want to know if it is possible with standard VS and be prepared for future requests (HTTP inspection) OR HTTP inspection doesn't make any sense with ssl pass-thru as LTM will not see packets/payload (encrypted). I have tried it with standard and it didn't work. - hoolio
Cirrostratus
Sure, it's possible to use a standard TCP VIP and not decrypt the SSL. It would be more efficient to use a Performance Layer 4 VIP though if you can do without SSL persistence. - Sly_85819
Nimbostratus
Aaron, can you tell me how to configure standard VIP for ssl pass-thru? - hoolio
Cirrostratus
If you want to use the efficiency of a FasL4 profile you give up the functionality of decrypting SSL using a client SSL profile and inspecting or modifying the HTTP using an HTTP profile. - Sly_85819
Nimbostratus
Does this mean that I cannot use Standard VS wherein the SSL cert is on the Server only? If I use standard VS with no Client profile or a Server SSL profile, the negotiation fails and the app never works. - hoolio
Cirrostratus
There are a few options (in order by what I think your requirements are): - Sly_85819
Nimbostratus
1. Standard TCP VIP without any client or server SSL using SSL session ID persistence. No HTTP inspection or modification possible - hoolio
Cirrostratus
When you say the app didn't come up using a standard TCP VIP and no client/server SSL profiles, what were the symptoms of the issue? Did the first request get a TCP response? Did the server receive an HTTP request? Did the client receive an HTTP response? - Sly_85819
Nimbostratus
App didnt come up -10:40:13.299685 802.1Q vlan4094 P0 198.147.192.8.37702 > 192.168.20.25.https: S 216133023:216133023(0) win 64512 (DF)
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects