Forum Discussion

Matt_35400's avatar
Matt_35400
Icon for Nimbostratus rankNimbostratus
Sep 16, 2007

SSL transparnecy

Hi All,

 

 

I was wondering if it is possible to configure Big IP in the following way?

 

 

2 or more web servers with SSL. 2 Big IP in failover, with 1 VIP for web servers. The client connects to the VIP with HTTPS which is balanced to one of the web servers. I don't want the F5 to offload the SSL, i want this to passthrough to web servers. Essentially having the Big IP only load balance.

 

 

I know it's better have the Big IP to offload the SSL, but this is what i've been asked to do...

2 Replies

  • You can absolutely have BIG-IP just do the load balancing without ssl offload. The only issue is that you will lose any sort of content inspection (ie, the BIG-IP will not be able to see any HTTP headers/cookies/payload/etc). So if you want to do custom persistence, routing, or redirection based the URI/hostname/cookies/form parameters/etc) you'll be out of luck. You have to be able to decrypt the traffic to be able to look inside of it.

     

     

    -Joe
  • Sorry to resurrect an old post, but how do you configure this?

     

     

    I've looked at simply not assigning Client or Server SSL profiles, but that doesn't seem to have helped..

     

     

    NVM, realised my mistake.. I'd left the HTTP profile in place, and this was obviously changing something as I got 'TLS error'...