Forum Discussion
David_L_
Sep 07, 2007Nimbostratus
SSL-Termination Persistence
I need to enable persistence for an SSL-terminated connection on a version 9.4.1 LTM.
The Configuration Guide and these forums indicate that SSL Persistence is not supported for SSL-terminated connections.
The Config guide indicates that:
To do this, you write an iRule using the HTTP::header command and then assign the iRule to the virtual server. Whenever the BIG-IP terminates an SSL request, the iRule inserts the certificate status as a header into the request, and persists the session based on that status. "
Unfortunately no examples are given, and I'm concerned about whether this method would persist connections after IE's periodic renegotiations.
I've thought about using a cookie hash on the existing JSESSIONID cookie generated by the application, but I can't see exactly how to do this - nor can I tell if the SSL termination would impact this.
Can anyone tell me the best way to manage persistence for SSL terminated connections? (Preferably with an example!)
Thank you very much.
David L.
- David_L_NimbostratusOK - To update this in case anyone is listening - I've copied/written/modified a rule that meets this requirement. There's one part I can't get to work correctly though - any thoughts would be appreciated.
- Colin_Walker_12Historic F5 AccountOnce SSL is terminated at the BIG-IP the connection can pretty much be handled like any other non-encrypted connection, meaning the way you do persistence is completely up to you.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects