Forum Discussion

m1978_295079's avatar
m1978_295079
Icon for Nimbostratus rankNimbostratus
Jun 27, 2017

SSL Passthrough on port

I want to configure SSL passsthrouHow to configure SSL passthrough on port 449. so client need to initiate https to VIP on port 449. and F5 will then talk back to server on 443. Is it possible without having any profile ?

 

2 Replies

  • The way to do that is by not using any profile, just the TCP one. Configure your VS to listen on port 449 and attach a pool to it. You may need SNAT the traffic. It may be a good idea to set the virtual server type as fastL4.

     

    By not selecting any L7 profile the BIGIP will send the traffic right to the pool members without interacting with any L7 protocol

     

  • To do SSL pass through you have to configure the VIP as Performance(Layer 4), it will not offload the certificate on LTM rather offloading will be done on the real servers behind LB.

     

    -- Pawan Chamoli