Forum Discussion
TLS handshake in passthrough scenario
You are correct. In a scenario where the load balancer does not perform ssl encryption/decryption (offloading), ssl negotiation is performed directly between the client and backend pool members (servers).
A typical F5 configuration would be comprised of a virtual server that listens on port 443, server type of standard or layer 4 and backend pool members listening on port 443.
If you are planning to use source IP persistence, my recommendation would be to use performance layer 4 as the virtual server type.
While F5 doesn’t have an official document on this setup, you’ll find that DevCentral is very useful with these types of questions.
Feel free to vote up my answer if this has been useful.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com