For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Nathaneil0227_2's avatar
Nathaneil0227_2
Icon for Nimbostratus rankNimbostratus
Jul 15, 2016

Virtual server not accessible using 443 but working using the backend port

Hi DC Expert/All,

 

Does anyone encounter this kind of issue. BTW I am using selfsigned certificates.

 

Thanks,

 

-Nat

 

11 Replies

  • Is the VS listening on port 443 or on all ports ? Does telnet work to VS on 443 ? Can you execute curl to the VIP ? Can you provide the configuration of the VS ?

     

  • Do you mean that for example if the pool member is configured to use port 4443 and you change the virtual server port to 4443 then it works? If this is the case, check that port translation is enabled on the virtual server.

     

    • Nathaneil0227_2's avatar
      Nathaneil0227_2
      Icon for Nimbostratus rankNimbostratus

      yes it works even though if you access the backend directly.

       

      Port translation is enabled.

       

      -Nat

       

  • Do you mean that for example if the pool member is configured to use port 4443 and you change the virtual server port to 4443 then it works? If this is the case, check that port translation is enabled on the virtual server.

     

    • Nathaneil0227_2's avatar
      Nathaneil0227_2
      Icon for Nimbostratus rankNimbostratus

      yes it works even though if you access the backend directly.

       

      Port translation is enabled.

       

      -Nat

       

  • Going to need a little bit more information.

     

    Presuming that you mean when you connect to the server directly, the page is working, but when traversing the LTM - it is not ?

     

    We'll need a bit more information - VIP configuration, have you established connectivity ? A TCPdump/wireshark taken on the VIP and possibly client machine.

     

    Regards Iain

     

    • Nathaneil0227_2's avatar
      Nathaneil0227_2
      Icon for Nimbostratus rankNimbostratus

      Ian Hi,

       

      Yes you are assuming it right.

       

      And yes I had established connectivity.

       

      -Nat

       

    • IainThomson85_1's avatar
      IainThomson85_1
      Icon for Cumulonimbus rankCumulonimbus

      Can you share your VIP configuration ? including all SSL Client information.

       

      What error do you get on the client ?

       

    • Nath's avatar
      Nath
      Icon for Cirrostratus rankCirrostratus

      Hi All,

       

      The issue is now escalated to escalation team of f5.

       

      Thanks

       

      -Nat