Forum Discussion

Rajaraman_12066's avatar
Rajaraman_12066
Icon for Nimbostratus rankNimbostratus
Oct 04, 2013

Site doesn't load while passing SSL traffic d to the web servers through F5.

All,

 

We are in the process of removing the SSL offloading config from F5. When i remove client SSL configuration and allow F5 to pass HTTPS traffic directly to the apache server , the page doesn't load. Alternatively if i access a web server directly bypassing F5, HTTPS page loads without any issues. Please advise.

 

5 Replies

  • You might also need to remove the HTTP profile from the virtual server, if you had one assigned (not uncommon in SSL offload configurations).

     

    • rob_carr's avatar
      rob_carr
      Icon for Cirrostratus rankCirrostratus
      Removing the HTTP profile will not prevent the BIG-IP from forwarding HTTP requests. Since HTTPS traffic is encrypted, the BIG-IP is unable to see the HTTP requests and simply load-balances the TCP connections.
  • You need to enable default server profile with Https Vip

     

    This is not entirely true. As Rob states, to allow SSL to flow through the box without offload, you need to remove BOTH client and server SSL profiles AND any layer 7 profiles (like HTTP) that may attempt to evaluate the unencrypted payload.