Forum Discussion
XFF licensing for https
Hello,
I have (maybe a simple) question about XFF in F5 BigIP. We have application that is using SSL (https) and we would like to activate de XFF option in our F5 and i would like to know if do we need a special license to activate the XFF for https?
Many thanks in advance for your reply.
4 Replies
- Kevin_Stewart
Employee
If you're referring to XFF header injection as provided in the HTTP Profile within LTM, then no there's no additional licensing. You cannot, however, insert an XFF header, or any header for that matter, if you do not offload the SSL at the LTM.
- zikovich_146574
Nimbostratus
Thanks for your quick reply. Sure we have to offload the SSL by using the private key of the application and then enable the XFF. Am i right?
- Kevin_Stewart
Employee
More or less, you are correct. Offloading client side SSL requires a client SSL profile applied to the virtual server. That client SSL profile must have, at a minimum, a server certificate and its corresponding private key. Enabling XFF header injection is a checkbox option in the HTTP profile: Insert X-Forwarded-For.
- zikovich_146574
Nimbostratus
OK Many thanks for your answers. I think the network team will be able to do it. I was just asking if we need a special license for this operation and your answer was clear "NO".
Reagrds,
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com