SSL Profiles Part 1: Handshakes
This is the first in a series of tech tips on the F5 BIG-IP LTM SSL profiles.
SSL Overview and Handshake
SSL Certificates
Certificate Chain Implementation
Cipher Suites
SSL Options
SSL...
Updated Mar 24, 2023
Version 2.0JRahm
Admin
Joined January 20, 2005
JRahm
Admin
Joined January 20, 2005
Nick_128577
Nov 18, 2014Nimbostratus
Nice but.... We have both client and server profiles enabled as we are inspecting the traffic as it comes through the F5. Our understanding is that the F5 terminates the secure connection from the outside world and makes a new secure connection internally to the downstream system in this model and that works fine until a very recent patch for WinShock. What we are seeing is that if we allow TLS1.2 externally but remove the capability internally then we are seeing issues with the site from an external prospective. Why is this occurring as surely the F5 should be handling this and not assuming that the downstream system needs to negotiate in the same way?