# Connecting a AWS Cloudfront Distribution Pool/Node to an F5 iApp

**URL:** <https://community.f5.com/t/connecting-a-aws-cloudfront-distribution-pool-node-to-an-f5-iapp/75376>\
**Category:** Technical Forums\
**Tags:** irules, aws, pools\
**Created:** [November 7, 2024, 10:22am UTC](https://community.f5.com/t/connecting-a-aws-cloudfront-distribution-pool-node-to-an-f5-iapp/75376 "2024-11-07T10:22:46Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![dhaasz](https://avatars.discourse-cdn.com/v4/letter/d/6a8cbe/32.png) [@dhaasz](https://community.f5.com/u/dhaasz)\
**Post date:** [November 7, 2024, 10:22am UTC](https://community.f5.com/t/connecting-a-aws-cloudfront-distribution-pool-node-to-an-f5-iapp/75376/1 "2024-11-07T10:22:46Z")

</div>

Hi there,

I was wondering if I could get some advice on connecting up AWS Cloudfront Distribution Pool/Node to an F5 iApp.

The iApp in question has a default pool of on premises servers but we have a requirement in that for a specific URL path then we instead forward onto a AWS Cloudfront distribution. The below is a snippet from the irule we currently have configured:

when CLIENT\_ACCEPTED {  
&nbsp; &nbsp; SSL::disable serverside  
}

when HTTP\_REQUEST  
{  
&nbsp; &nbsp; if {([HTTP::uri] starts\_with “/falc/”)}&nbsp;  
&nbsp; &nbsp; {  
&nbsp; &nbsp; &nbsp; &nbsp; SSL::enable serverside  
&nbsp; &nbsp; &nbsp; &nbsp; HTTP::header replace Host “[d2s8lx2sdbghef.cloudfront.net](http://d2s8lx2sdbghef.cloudfront.net)”  
&nbsp; &nbsp; &nbsp; &nbsp; pool [d2s8lx2sdbghef.cloudfront.net](http://d2s8lx2sdbghef.cloudfront.net)  
&nbsp; &nbsp; }  
}

The pool and the FQDN node are showing green which means F5 can resolve the addresses. However when we attempt to go to a URL which starts with the prefix above instead of being direct to the Cloudfront distribution (and the S3 content behind) we instead get the following:

 ![image_336221.png](https://d20hrnpixdzcsd.cloudfront.net/original/3X/4/e/4eed0f68832e6a832c6b6300fe8345b760572ca2.png)

Check and the distribution has redirect HTTP to HTTPS configured on the behaviour and we are attempting to replace the Host with the matching distribution.

I was wondering if this has been encountered by anyone before, if anyone has attempted anything similar and if able to get it working how that was achieved.

Thank you in advance of any assistance that may provide.
