Forum Discussion

m__craft's avatar
m__craft
Icon for Nimbostratus rankNimbostratus
Sep 18, 2013

Cisco CSS to F5

We are currently migrating our Cisco CSS devices to a pair of F5 LTM's. The question I have is regards to the CSS Groups and SSL-Proxy List. I am not sure what they translate to on the F5 side. Would the CSS Groups convert to SNAT Pools or would they just become Virtual Servers? Any help would great.

 

3 Replies

  • Yes, CSS groups correspond to SNAT pools. SSL proxy list doesn't have a direct translation, but you'd enable SSL proxy on the virtual server by importing the certificate/key pair and then creating client and server SSL profiles using this cert/key pair. Then apply the SSL profiles to the virtual server.

     

    • Cory_50405's avatar
      Cory_50405
      Icon for Noctilucent rankNoctilucent
      I should add that the BIG-IP also has an "SNAT automap" feature which will automatically select a SNAT if no pool is specified. Depending on your environment, this may work rather than setting up multiple SNAT pools.