Forum Discussion
John_Krum
Cirrus
Jul 07, 2021Policies to move HTTPS traffic
I am trying to share a 443 NAT on a firewall sending traffic to the LTM. Once it gets to the F5 I want formview.xxx.org to go to pool-Forms and WEBview.xxx.org to go to pool-WEB. Is that possible wit...
John_Krum
Cirrus
Jul 07, 2021I have looked at the first reference link earlier as well. Here is more detail regarding what I am trying to accomplish.
I have a outside firewall NAT for incoming 443 traffic on 96.103.236.222 that forwards that traffic to a LTM VIP 192.168.5.5 listening on 443.
I am trying to have sites
Viewforms.mycompany.org
And
Employee.mycompany.org
(I am also thinking it might be better to do
Mycompany.web.org/viewforms
And
Mycompany.web.org/employees
But the first one is preferred)
The VIP is basic.
HTTP profile is HTTP – I have to select a http or a http-connect profile (this is where I am not sure why I require an http profile, it makes me think that the server connection is http)
Automap
Resources
I don’t have a default pool selected (I did to verify I get the login page prior to adding a policy)
Policy is DMZ-Cop
DMZ-Cop is
Match
HTTP Host -> host -> is -> any of -> Viewforms.mycompany.org or viewforms -> at request time
Do the following
Forward traffic -> to pool -> viewforms-pool
When I https to the page Viewforms.mycompany.org I do not see any policy statistics, invoked or succeeded.
I haven’t tried adding any info for the second site.
Once I change the VIP config http profile (client) to http – I no longer connect to the login page. I do see TCP handshake, Client Hello, and an ACK to that. 1.5 seconds later a FIN from my side.
Thanks
John Krumenacher
Daniel_Wolf
MVP
Jul 13, 2021I am not quite sure if I understand you. You took a capture accessing the webserver directly and another one accessing via the BIG-IP.
What is missing in the capture you took on the BIG-IP? The handshake between your client and the BIG-IP, or between the BIG-IP and server?
Can you share some snippets from your config and/or the captures?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects