# Using iRules to conserve public IP addresses

**URL:** <https://community.f5.com/t/using-irules-to-conserve-public-ip-addresses/463>\
**Category:** Technical Forums\
**Tags:** irules, devops, data-groups, application-delivery\
**Created:** [October 14, 2013, 4:09pm UTC](https://community.f5.com/t/using-irules-to-conserve-public-ip-addresses/463 "2013-10-14T16:09:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![donmon\_10187](https://avatars.discourse-cdn.com/v4/letter/d/b77776/32.png) [@donmon\_10187](https://community.f5.com/u/donmon_10187)\
**Post date:** [October 14, 2013, 4:09pm UTC](https://community.f5.com/t/using-irules-to-conserve-public-ip-addresses/463/1 "2013-10-14T16:09:30Z")

</div>

Hello all,

I’ve been tasked with coming up with a solution using one public IP address and laod balancing it to multiple pools using iRules and host-headers. Currently, we’re doing a one to one NAT. I created a virtual server and used the iRule below, which is using Data Groups. I was able to successfully accomplish this for http but I cannot get https to work. If anyone can provide some input, I’d much appreciate it.

```tcl
when HTTP_REQUEST {
if { [class match [string tolower [HTTP::host]] equals TestRedirect] } {
  set usepool [class match -value [string tolower [HTTP::host]] equals TestRedirect]
  pool $usepool
}
}

```

Here is the Data Group for the http pools.

```tcl
ltm data-group internal /Common/TestRedirect { 
    records { 
        TESTA.net { 
            data TESTA_80_pool 
        } 
        TESTB.org { 
            data TESTB_80_pool 
        } 
        TESTC.com { 
            data TESTC_80_pool 
        } 
    } 
    type string 
}

```

---

<div class="post-metadata">

**Author:** ![Lee\_Payne\_53457](https://avatars.discourse-cdn.com/v4/letter/l/b5a626/32.png) [@Lee\_Payne\_53457](https://community.f5.com/u/Lee_Payne_53457)\
**Post date:** [October 14, 2013, 4:17pm UTC](https://community.f5.com/t/using-irules-to-conserve-public-ip-addresses/463/2 "2013-10-14T16:17:40Z")

</div>

The only way this would work is if you had a SSL certificate containing SAN’s for each domain you want to use for your iRule, without a proper SSL cert to decrypt the traffic what you want to do is impossible.

---

<div class="post-metadata">

**Author:** ![nathe](https://avatars.discourse-cdn.com/v4/letter/n/eb8c5e/32.png) [@nathe](https://community.f5.com/u/nathe)\
**Post date:** [October 14, 2013, 4:22pm UTC](https://community.f5.com/t/using-irules-to-conserve-public-ip-addresses/463/3 "2013-10-14T16:22:40Z")

</div>

Would it be impossible? You’d need a client SSL profile so the f5 can decrypt the traffic so the irule can inspect the http traffic. Then if there is a cert mismatch wouldn’t you just get the certificate warning in the browser and need to click on Continue? Not pretty of course so yes, you’d want a wildcard cert of some description.

---

<div class="post-metadata">

**Author:** ![Lee\_Payne\_53457](https://avatars.discourse-cdn.com/v4/letter/l/b5a626/32.png) [@Lee\_Payne\_53457](https://community.f5.com/u/Lee_Payne_53457)\
**Post date:** [October 14, 2013, 4:24pm UTC](https://community.f5.com/t/using-irules-to-conserve-public-ip-addresses/463/4 "2013-10-14T16:24:10Z")

</div>

I was assuming that they wanted it to be seamless rather than present a cert error but you are correct, if you didn’t mind the cert error appearing any cert applied to a client SSL profile would work for this.

---

<div class="post-metadata">

**Author:** ![donmon\_10187](https://avatars.discourse-cdn.com/v4/letter/d/b77776/32.png) [@donmon\_10187](https://community.f5.com/u/donmon_10187)\
**Post date:** [October 14, 2013, 4:51pm UTC](https://community.f5.com/t/using-irules-to-conserve-public-ip-addresses/463/5 "2013-10-14T16:51:57Z")

</div>

Thanks for the information guys. I’ll explore the options. Seamless is what we’d want but I’ll need to build the solution first and go from there.
