cancel
Showing results for 
Search instead for 
Did you mean: 

F5 GTM (DNS) & monitor mTLS endpoint

CCM
Nimbostratus
Nimbostratus

Is there a way to configure a F5 GTM/DNS to have HTTPS heath monitors to send the F5 GTM device certificate by default, if the GTM monitor is requesting client certification due to the endpoint being mTLS enabled?

 

do not want to maintain/configure a custom client certificate to monitor mtls enabled endpoints.

2 REPLIES 2

F5SJ_
Altocumulus
Altocumulus

HTTPS health monitor for probing the virtual servers? In case you have BIG IP deployment of LTMs in the GTM you can skip monitoring but if it is a Generic host than you have 443 open between int self ip (non floating) and the server and then you can use default or custom https monitor.

Grumpy_Cat
Cirrus
Cirrus

Hi CCM,

 

You would need to import your device cert/key into the SSL certificate list and then you'll be able to select the device cert/key to use for HTTPS health monitors.

 

cert/key location:

/config/httpd/conf/ssl.crt/server.crt

/config/httpd/conf/ssl.key/server.key

 

Kind regards

Ben