Forum Discussion

Jesse_Reinhart_'s avatar
Jesse_Reinhart_
Icon for Nimbostratus rankNimbostratus
Aug 07, 2018

HTTP/HTTPS pass through with no certificate

Hi!

 

We're using a couple of Big-IP instances in AWS to perform HTTP redirection for some of our clients. Their only purpose is to redirect domain root visitors to the site's WWW record, which points to our HA pair in our data center where the web servers live.

 

We've been deploying SSL certificates to each of these redirecting Big-IPs since we need to be able to redirect on HTTPS. However, managing all of the certificates on multiple Big-IPs is getting out of hand.

 

I'd like to be able to set up the virt on the Big-IPs in AWS to use the HA pair as their source - as a sort of pass through. I've tried multiple options which seem to be correct, but it's not working correctly. I believe where we're getting hung up is with SNAT - the responses from the HA pair are going to the private IP address of the AWS Big-IP and not going back to their actual destination.

 

Does anybody have experience with this sort of setup? Essentially it's a WAN LB with SSL pass through.

 

Thanks!

 

Jesse

 

2 Replies

  • Hi Jesse, Generally, you just need to setup VS Type "Performance (HTTP)" or "Standard" with no SSL Profile selected. Specifically, i don't know about your setup.

     

    Best Regards,

     

    • Jesse_Reinhart_'s avatar
      Jesse_Reinhart_
      Icon for Nimbostratus rankNimbostratus

      Thanks, I'll give that a shot and let you know what the results are.