Forum Discussion

Jesse_Reinhart_'s avatar
Jesse_Reinhart_
Icon for Nimbostratus rankNimbostratus
Sep 08, 2017

SNI - no SSL profile = drop/reset

Hi!

 

I've got SNI working properly on my LTM virts. It's working fine, but some of the sites we host through that virt don't have SSL. Those sites don't have an SSL profile or certificate to present, so true to SNI, it presents the default SSL profile, which is a wildcard certificate for a different domain. This throws some errors in the visitor's browser, which is expected given the actions that are occurring.

 

Is there a way that I can have the Big-IP do something different with the connection when there's no matching SSL profile instead of presenting the wrong certificate?

 

Thanks!

 

  • Jesse

3 Replies

  • I faced a similar problem . We had a SSL certificate for but when user hitting on XYZ.com they were getting cert error so i created two SSL profile with the same certificate and in one profile i used SNI as and in other profile i used SNI as XYZ.com . Then attached both profile to the VIP

     

    • Jesse_Reinhart_'s avatar
      Jesse_Reinhart_
      Icon for Nimbostratus rankNimbostratus

      Thanks for the response! What I'm looking for is actually to see if the VIP can drop traffic if there's not an SSL profile/certificate for that domain, rather than providing the default SSL profile since that causes a certificate mismatch warning.