F5-SSL connection mirroring

When we enable connection mirroring on a virtual server that references an SSL profile, the BIG-IP system mirrors SSL-specific data to the appropriate device group member. This preserves SSL connections when failover occurs.

  1. Enable the statemirror.secure database variable on the active
    1. #tmsh
    2. #modify /sys db statemirror.secure value enable
  2. Configure connection mirroring for the virtual server using the Configuration utility
a.    Log in to the Configuration utility.
b.    Navigate to Local Traffic > Virtual Servers.
c.    Click the appropriate virtual server.
d.    In the Configuration list, select Advanced.
e.    Select the Connection Mirroring check box.
f.     In the SSL profile section, confirm that the appropriate SSL profile is in the Selected box.
g.  Click Update.

3. Viewing SSL mirroring statistics:
    1. #tmsh
    2. #show /ltm profile client-ssl <profile_name>

No comments:

Post a Comment