Forum Discussion
Where are the F5 SSL Orchestrator (SSLO) SplitSession Client/SplitSession Server profiles used?
- Oct 07, 2022
Splitsession profiles are used to convey flow information, signaling, for the traffic that leaves the BIG-IP to pass through the security services. For inline L2/L3 services, flow is used (5-tuple src:dst addr:port proto). Flow signaling can't work across an HTTP (proxy) devices because a proxy will always minimally change the source port, and usually some of the other values. So for HTTP services it uses an HTTP header to track the flow across the service. To my knowledge, session flow isn't used.
Splitsession profiles are used to convey flow information, signaling, for the traffic that leaves the BIG-IP to pass through the security services. For inline L2/L3 services, flow is used (5-tuple src:dst addr:port proto). Flow signaling can't work across an HTTP (proxy) devices because a proxy will always minimally change the source port, and usually some of the other values. So for HTTP services it uses an HTTP header to track the flow across the service. To my knowledge, session flow isn't used.
Kevin_Stewart I thought that you may give me the reply as you are an SSLO expert. Thanks 😀
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com