Forum Discussion

IDRES_Tarek_329's avatar
IDRES_Tarek_329
Icon for Nimbostratus rankNimbostratus
Nov 13, 2017

Multi Certificate LTM

We have a VS with multiple pools. We redirect to the right pool using a Policy. For each pool (web app) we have a dedicated certificate. The certificate are added in the ssl profile which are added to the VS. Then in each VS we have multiple pools and multiple ssl profiles. My question is : How the F5 know what ssl profile (certificat) applies to what pool ? Does it check the CN or the SAN of the certificat?

 

Thanks guys

 

1 Reply

  • It uses SNI feature.

     

    you can see that one profile have Default for SNI enabled. this is the default profile if SNI doesn't match any certificate.

     

    look at this article about which certificate attribute is used by SNI