Forum Discussion
rpalacios_79340
Altostratus
May 19, 2009Terminating SSL on F5.
Hello guys,
I read that you can use the F5 to offload SSL certificate-verification tasks from client and server systems.
I have a few questions about this configuration;
1. How painful is this process in terms of the configuration changes I would have to apply to the current virtual servers?
2. Are there any real advantages on moving the security certificates from my web servers to the F5?
3. Would a client-side profile be enough or would it have to be client-side profile and Server-side profile?
4. Can I just import or install the same certificates I have on the web servers or does the F5 need to have its own certificate in addition the certificates of the web servers?
Thanks,
-Reinhard
- James_Quinby_46Historic F5 Account1. Not painful at all. You'd need a virtual server listening on port 443, and then assign an SSL profile to it which referenced the certificate and key.
- dennypayne
Employee
Oh, and regarding point 2, the other advantage is that if you are doing SSL offload, you can then use Layer 7 iRules and cookie persistence and other fun Layer 7 stuff. If you are passing SSL connections through the LTM to the webservers without doing offload, you can't "see" into the encrypted packets and thus you are restricted to Layer 4 iRules and source IP persistence. - James_Quinby_46Historic F5 AccountYeah. Reversed. I always do that. Sorry for any confusion. :|
- rpalacios_79340
Altostratus
jquinby and Denny, - vravula_235006
Nimbostratus
Hi, For having server-side SSL profile we do need a certificate installed on the web server right?
- Kevin_Stewart
Employee
For having server-side SSL profile we do need a certificate installed on the web server right?
It'd be difficult to even enable SSL in any given application without also applying a certificate and corresponding private key. So yes, you do need a certificate (and private key) on the web server.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects