Forum Discussion
rafaelbn_176840
Altocumulus
Jan 27, 2019Troubleshooting PFS - BIG-IP Feature Request?
Hello all!
Ever since I heard of PFS I started dreading the day I would need to troubleshoot a PFS flow.
I read some interesting suggestions of how to deal with it. One could make SSL bridg...
DennisJann
Nimbostratus
Jan 31, 2019You can capture the SSL session keys with an iRule while running tcpdump on the BIG-IP, and then use the Master Secret log file to view the decrypted tcpdump data in Wireshark.
K16700: Decrypting SSL traffic using the SSL::sessionsecret iRules command
The instructions in the KB article do work for decrypting PFS sessions.
If your HTTPS VIP is running on a non-standard port, you would need to go into Wireshark preferences and add the non-standard HTTPS port in Protocols > HTTP > SSL/TLS Ports.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects