Forum Discussion

J_Drew_160974's avatar
J_Drew_160974
Icon for Nimbostratus rankNimbostratus
Jun 25, 2014

LTM 11.x - Multiple SSL polices in one virtual

Hi

 

We have an F5 with a single SSL virtual which has 3 websites (lets refer to them as PROD/UAT/PP) behind it. each website has its own server entrust certificate.

 

We have created the certs and loaded them into the profiles. if we do the openSSL tests to the frontend interface the certs resolve ok.

 

The profiles are referenced as Prod-profile/UAT-profile/PP-profile and are stated in that order in the virtual. When a request comes into the virtual for a page on the PP website there are hits on the Prod-profile, but not on the UAT-profile or PP-profile.

 

We get a 'server hangup' webpage returned, we know the website does work and we even had it working through the F5 for about 30 mins before we changed the irules that were assigned to the virtual.

 

Is there anything we need to know about multiple profiles assigned to one virtual on version 11?

 

1 Reply

  • Hi,

     

    You can use SNI :

     

    • http://support.f5.com/kb/en-us/solutions/public/13000/400/sol13452.html?sr=38453862
    • https://devcentral.f5.com/articles/multiple-certs-one-vip-tls-server-name-indication-via-irules
    • https://devcentral.f5.com/questions/multiple-ssl-client-profiles-for-one-virtual-server