Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

How to get multiple SSL sites working on IIS5 with NLB.

Posted on 2001-07-25
6
Medium Priority
?
293 Views
Last Modified: 2007-12-19
I am running 2 x Win2k Adv. Servers with NLB. I have multiple sites on the servers, most sharing an IP address.
I now need a few of those sites to use SSL, so I have got SSL certs from VeriSign, and moved those sites to a unique IP address.

However, I have NAT going on in the firewall, which points the external IP addresses to a single NLB IP address inside. I think however, that IIS may want the SSL sites to have a unique internal IP address as well, I'm not sure.
When I enable SSL for a site, it only works if I get it to use the (All Unassaigned) IP address. After that, all SSL traffic for all sites ends up at the one that catches the Unassagined IP's.
Assigning SSL to it's unique external IP address doesn't seem to do the trick, prob. because the external IP address is now only available in the hostname, which is encrypted in SSL, and unavailable?

I think the solution lies in mapping the unique external IP's to unique internal IP's. Unfortunately, there is only 1 NLB IP address, so unless I can add more, I don't know what to do.

Anyone know how to get around this?
0
Comment
Question by:roddy
6 Comments
 
LVL 5

Expert Comment

by:dredge
ID: 6318088
listening.
0
 
LVL 9

Accepted Solution

by:
TTom earned 1200 total points
ID: 6319707
Can you map the (many) external IP addresses to the (single) internal IP address, but using different ports and configure IIS for each of the sites to use the same IP address, but a different port?

(Not sure I really understand the problem, so this may be off base.)

Tom
0
 
LVL 5

Expert Comment

by:dredge
ID: 6319744
perhaps when the internal user wants to log onto the secure port, you'll simply have to send them through your firewall and allow them to point at the public IP address.
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 
LVL 37

Expert Comment

by:meverest
ID: 6320965
SSL requires a unique IP address/port because the protocol does not support http1.1-like hostname headers to identify the virtual host.

now if you are using a port map on the NAT router, then you can only have one address per port, so to get multiple ssl sites working on your internal web server, you have two options:

1. use a different port for each virtual server, and then set up additional port-to-internal-address maps on the NAT, eg,
assuming your NAT router address is 1.2.3.4 and the internal web server is 192.168.1.1, add these maps:

1.2.3.4 port 443 -> 192.168.1.1 port 443
1.2.3.4 port 1443 -> 192.168.1.1 port 1443
1.2.3.4 port 2443 -> 192.168.1.1 port 2443

2.  set up the NAT with multiple public addresses, and map port 443 to multiple virtual servers on the internal; network, eg:

assuming your NAT router address has 1.2.3.4, 1.2.3.5, and 1.2.3.6 and the internal web server has 3 virtual servers mapped to 192.168.1.1, 192.168.1.2, 192.168.1.3, add these maps:

1.2.3.4 port 443 -> 192.168.1.1 port 443
1.2.3.5 port 443 -> 192.168.1.2 port 443
1.2.3.6 port 443 -> 192.168.1.3 port 443

your main problem is to get access to additional address space, or you will need to use different ports, so that when accessing, it will look like this in the browser:

https://server1.domain.com
https://server2.domain.com:1443
https://server3.domain.com:2443

etc.

cheers.


 
0
 

Author Comment

by:roddy
ID: 6321414
I'm going to try using different ports for each external IP address. Just looking at this idea makes me very confident it will work.
IIS actually seems designed with this in mind, now that I look at it this way. Specifying your secure port is very easy.

This will take me a few hours to implement, so points will be given afterwards.

TTom got in first with this answer, and while meverest gave a very complete answer, it wasn't exactly what I wanted. These are the mappings that TTom had in mind, and is what I'll be trying.

1.2.3.4 port 443 -> 192.168.1.1 port 443
1.2.3.5 port 443 -> 192.168.1.1 port 1443
1.2.3.6 port 443 -> 192.168.1.1 port 2443
0
 

Author Comment

by:roddy
ID: 6337496
Yep, this is working fine. I just feel stupid I didn't think of it myself...

Anyway, thanks for your help. Sorry for the delay in giving points.

Rod
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Logparser is the smartest tool I have ever used in parsing IIS log files and there are many interesting things I wanted to share with everyone one of the  real-world  scenario from my current project. Let's get started with  scenario - How do w…
When it comes to showing a 404 error page to your visitors, you do not want that generic page to show, and you especially do not want your hosting provider’s ad error page to show either. In this article, I will show you how to enable the custom 40…
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an anti-spam), the admin…
Suggested Courses
Course of the Month12 days, 6 hours left to enroll

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question