Solved

F5 BIG-IP SSL and non-SSL

Posted on 2011-09-28
3
335 Views
Last Modified: 2012-05-12


We are looking to implement a solution whereby users must use SSL to access a particular web app if they have the correct client cert. For users who don't have the cert yet we want the solution to automatically revert to use HTTP for this app and continue. We want it to be seamless to the user.

We plan on using the BIG-IP for the SSL termination at the perimeter.

Can the big-ip detect that the users machine doesn't have the cert and redirect to http? Or am I way off course here? Are there other ways to do this?
0
Comment
Question by:58872
3 Comments
 
LVL 82

Expert Comment

by:Dave Baldwin
Comment Utility
You'll probably have to ask BIG-IP.  The general problem you are facing is that when you request an SSL connection, it gets negotiated First before anything else.  If it fails, you don't get anything but an error.  That would be normal.  Maybe BIG-IP can do something else.
0
 
LVL 16

Accepted Solution

by:
SteveJ earned 500 total points
Comment Utility
Yes, you can redirect based on an SSL negotiation error. The problem is that will defeat the purpose of requiring a specific client cert unless you also filter on the source IP address. That is, 'sneaky pete' wants access to your app but doesnt have the appropriate cert. You end up effectively giving it to him.

What am I missing?

Steve
0
 

Author Closing Comment

by:58872
Comment Utility
Thanks
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now