Forum Discussion

rsacheen's avatar
rsacheen
Icon for Nimbostratus rankNimbostratus
Mar 14, 2017

BIG-IP SSL related error/access logs

In case of SSL termination (HTTPS offloading), is there a way to find out if the client is being blocked by BIG-IP because of http://.. access. Does BIG-IP output any SSL related authentication error/access logs?

 

We have HTTPS web service (https://example.jp/). We doubt that our client tried to access through http://example.jp/

 

Does BIG-IP produce any logs/hints in case like above? How does BIG-IP respond to case like above?

 

We would be grateful if anyone could provide us with the answer/knowledge. Thank you!

 

4 Replies

  • Its default behaviour of LTM to drop connection if http(vip) doesn't exist. If you wanted to track http connection then create http vip n apply irule with drop condition and send client log to ltm. Does it makes sense?

     

    Other option to redirect all connection to https vip n take client IP log.

     

    • rsacheen's avatar
      rsacheen
      Icon for Nimbostratus rankNimbostratus

      Thank you for the reply jhaas! Want to know whether LTM produces any logs when the connection is dropped. About tracking HTTP connection and redirection to HTTPS VIP, I shall try it later. Thanks!