Forum Discussion

cymru81's avatar
cymru81
Icon for Altocumulus rankAltocumulus
Jul 24, 2017

ssl pools

Hi, i dont even know if this is a supported config. We have a VIP listening on TCP443 thats doing ssl offload (certificate on LTM too) and we want the traffic sent to a pool with its members listening on TCP443 too. Have tested and it doesnt work. Does it need and specific ssl profiles or health monitors?

 

2 Replies

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    If the backend pool members are expecting SSL then you need add a Server SSL Profile to the VIP config. The default serverssl profile should do it (in most cases).

     

    Hope this helps,

     

    N

     

  • Hello Cymru,

     

    Please verify that you have applied a client SSL profile and a server SSL profile on the VS.

     

    Just to clarify, when you say "SSL Offloading" this means that you only encrypt trafic between the "client and the VIP". In this case you will only put an "client SSL profile" on your VS

     

    But if your backends/servers listen on 443 I think that they probably wait for an SSL handshake from the F5. So you will need to add also "server SSL profile" on your VS.¨

     

    Regards