Forum Discussion

MSK_222682's avatar
MSK_222682
Icon for Nimbostratus rankNimbostratus
Jul 01, 2016

Leveraging SSL connections between BIG IP LTM and backend servers

Hi Team,

 

I have a scenario, wherein the SSL worker threads on the backend servers are being exhausted while processing all the SSL requests between BIG-LTM and the backend servers.

 

I'm looking at some options/settings on BIGIP which can leverage already open SSL connections with backend servers so as to not bombard the backend servers with too many SSL handshake requests.

 

I see OneConnect profile can leverage the already existing idle connections between LTM and backend server but not sure if it can used for leveraging open SSL connections as well. The idea is to reduce the number of encryption/decryption mechanism on the backend server.

 

Can anyone provide their expertise to achieve this.

 

BR, MSK

 

1 Reply

  • Hi, Oneconnect is the key, otherwise you can play with caching for http content. As an addition depending on you server behavior when overloaded by ssl connection , you can apply some limit on the maximum number of connections allowed by member.