SSL Pass Through VS for Safari Clients
We're experiencing an issue with a VS in our configuration which is performing SSL pass through. Clients attempting to connect to our site via Safari (from a Mac) are unable to successfully complete an SSL handshake with F5. Packet traces show that syn/ack happens fine. The client (Safari) then sends a client hello which is ack'd by F5. The very next packet in the trace, however, is consistently a RST, terminating the handshake.
We are planning on making some changes to our site configuration in the near future which will allow us to perform SSL termination. This handshake issue with Safari clients magically disappears in our test environment when we enable SSL termination.
Prior to moving this infrastructure behind F5, Safari clients were able to visit the site without problems.
In the mean time we are really just looking for some sort of temporary workaround to appease our Safari clients.
We currently have a ticket open with F5 support on the issue but I figured I would post here and see if anyone else has run into similar issues. Whether you have or have not I'm open to suggestions if anyone has any.
Currently running 11.1.0 HF2 on a Big-IP 3900. The machine I have available to test with is running Safari Version 5.1.7 (7534.57.2) on OSX 10.7.4. The exact same Safari version running on a PC works fine.
If you need any further info or clarification, let me know.