Forum Discussion
Forrest-Z
Cirrus
Apr 11, 2025Why does SSLO not support ACTIVE-ACTIVE mode deployments?
Why does SSLO not support ACTIVE-ACTIVE mode deployments?
Kevin_Stewart
Employee
May 09, 2025There are a few official and technical answers to this question:
- Officially, SSLO policy on (classic) BIG-IP is a function of the Access per-request-policy engine, and APM itself does not support active-active in this way.
- Technically, it does not make sense to do active-active for outbound traffic, since an active-active configuration assumes multiple listener configurations (src:dest:port:proto:vlan) is alive on one of the BIG-IPs, and an outbound SSLO will typically only have one listener configuration (0.0.0.0/0:0 for transparent proxy, x.x.x.x:3128 for explicit proxy).
But the point is valid about splitting ipv4 and ipv6, and BIG-IP Next will indeed support active-active configurations, as SSLO is becoming a native module (no iAppLX on Next).
- Forrest-ZMay 13, 2025
Cirrus
Thank you so much for your answers!
It was great.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects