Forum Discussion
Matt_35400
Nimbostratus
Sep 16, 2007SSL transparnecy
Hi All,
I was wondering if it is possible to configure Big IP in the following way?
2 or more web servers with SSL. 2 Big IP in failover, with 1 VIP for web servers. The client connects to the VIP with HTTPS which is balanced to one of the web servers. I don't want the F5 to offload the SSL, i want this to passthrough to web servers. Essentially having the Big IP only load balance.
I know it's better have the Big IP to offload the SSL, but this is what i've been asked to do...
2 Replies
- You can absolutely have BIG-IP just do the load balancing without ssl offload. The only issue is that you will lose any sort of content inspection (ie, the BIG-IP will not be able to see any HTTP headers/cookies/payload/etc). So if you want to do custom persistence, routing, or redirection based the URI/hostname/cookies/form parameters/etc) you'll be out of luck. You have to be able to decrypt the traffic to be able to look inside of it.
-Joe - Ian_Amos_37833
Nimbostratus
Sorry to resurrect an old post, but how do you configure this?
I've looked at simply not assigning Client or Server SSL profiles, but that doesn't seem to have helped..
NVM, realised my mistake.. I'd left the HTTP profile in place, and this was obviously changing something as I got 'TLS error'...
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
