Forum Discussion
Fletcher_Cocquy
Nimbostratus
Mar 15, 2010SSL Proxy Juniper SSL VPN
Hi, we are not ready to expose our Juniper SSL VPN externally, so I was asked to test the BigIP's capability (its already exposed externally) to proxy SSL to it.
I setup the external HTTPS virtual server, and mapped to the pool of one consisting of the Juniper SSL VPN's IP port 443 (note this is different than our normal case where we want to offload the SSL - here we want to pass on the HTTPS)
Anyway, the Juniper is denying the requests from the BigIP with messages:
SSL negotiation failed while client at source IP 'xx.yy.104.107' was trying to connect to 'aa.bb.70.132'. Reason: 'http request'"
which does not make sense to us since the request is coming on port 443 from the BigIP.
Is there a setting I'm forgetting in the BigIP to make this SSL==>SSL proxy work?
thanks
- Fletcher_Cocquy
Nimbostratus
Hi, thanks for the reply - Ryan77777
Altocumulus
I'm having similar issues. I'm going to try the layer-2 approach though since it's on the same network. Did you ever get the layer-3 profile working? Would be curious to know what the solution was. - Krzysztof_Kozlo
Nimbostratus
We specifically had issues with the LTM doing SSL termination and re-encryption in front of the Juniper SA-series SSL VPN appliance (formerly known as Neoteris IVE) on version 9.4.8.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects