Forum Discussion

CCM's avatar
CCM
Icon for Nimbostratus rankNimbostratus
May 28, 2020

F5 GTM (DNS) & monitor mTLS endpoint

Is there a way to configure a F5 GTM/DNS to have HTTPS heath monitors to send the F5 GTM device certificate by default, if the GTM monitor is requesting client certification due to the endpoint being mTLS enabled?

 

do not want to maintain/configure a custom client certificate to monitor mtls enabled endpoints.

2 Replies

  • HTTPS health monitor for probing the virtual servers? In case you have BIG IP deployment of LTMs in the GTM you can skip monitoring but if it is a Generic host than you have 443 open between int self ip (non floating) and the server and then you can use default or custom https monitor.

  • Hi CCM,

     

    You would need to import your device cert/key into the SSL certificate list and then you'll be able to select the device cert/key to use for HTTPS health monitors.

     

    cert/key location:

    /config/httpd/conf/ssl.crt/server.crt

    /config/httpd/conf/ssl.key/server.key

     

    Kind regards

    Ben