Forum Discussion
Michael_Jenkins
Mar 08, 2015Cirrostratus
Since you're having multiple hosts go to the same VIP, you'll need to have the client cert (your SAN) on the primary VIP, so it can offload the SSL. You could also have the SAN cert on your secondary VIPs and a default cert as the serverssl cert on your primary VIP if you wanted to secure communication to the secondary VIPs (though since it's internal to the device, I don't think that it would matter since the traffic never leaves the BIG-IP between those two).
Regarding inheritance, the VIPs would be set up separately, so they'll each have their own iRules, profiles, etc... Basically they're configurations will be completely separate.