Forum Discussion
Luca_55898
Nimbostratus
Jul 28, 2012x-forwarded-for, ok with HTTPS?
Hi,
Can you use the X-Forwarded-For option if the virtual server is a HTTPS server doing SSL
offload?
The virtual server is configured on port 443, with a client SSL cert. The pool members are also on port 443. I have enabled the X-Forwarded-For option in a custom HTTP profile and assigned that to the VS, however the customer says its not working correctly.
3 Replies
Sort By
- Hamish
Cirrocumulus
You can if you decrypt the SSL session on the BigIP (SSL Offload) because the BigIP needs the decrypted stream to be able to add content to the headers. - Luca_55898
Nimbostratus
The pool members are on 443, but not sure if they are doing SSL. I haven't configured a server side cert.So i change the pool members to be port 80, and configure SSL offload as per normal on the F5, can I just do x-forwarded-for like norma (using a HTTP profile?)
- Hamish
Cirrocumulus
It'd be unusual for port 443 NOT to be doing SSL. You shouldn't need a server side cert... Just one for the client-side SSL (i.e. the connection FROM the client).
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects