VMware VCLOUD SDK FOR JAVA 1.0 - DEVELOPER S GUIDE Manuale Utente Pagina 62

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
  • Pagina
    / 65
  • Indice
  • SEGNALIBRI
  • Valutato. / 5. Basato su recensioni clienti
Vedere la pagina 61
Hybrid Cloud Application Architecture
F5
®
Deployment Guide 60
Appendix C: Configuring the BIG-IP LTM to offload
SSL
If you are using the BIG-IP LTM system to offload SSL from the Apache
devices, there are additional configuration procedures you must perform on
the BIG-IP LTM system.
Important
Offloading SSL is not typically required inside of the firewall(s). We are
including the instructions here for reference.
This section is optional, and only necessary if you are using the BIG-IP
LTM system for offloading SSL.
In the following configuration, the BIG-IP LTM redirects all incoming
traffic to the HTTP virtual server to the HTTPS virtual server. This is useful
if a user types a URL in a browser, but forgets to change the protocol to
HTTPS.
If your deployment does not require all traffic to be redirected to HTTPS,
you do not need to configure the iRule or modify the HTTP virtual server as
described below, nor configure the Rewrite Redirect setting in the HTTP
profile in Step 5 of
Creating an HTTP profile. You can have both an HTTP
and HTTPS virtual server on the same address with the appropriate ports.
Using SSL certificates and keys
Before you can enable the BIG-IP LTM system to act as an SSL proxy, you
must install a SSL certificate on the virtual server that you wish to use for
Apache connections on the BIG-IP LTM device. For this Deployment
Guide, we assume that you already have obtained an SSL certificate, but it is
not yet installed on the BIG-IP LTM system. For information on generating
certificates, or using the BIG-IP LTM to generate a request for a new
certificate and key from a certificate authority, see the Managing SSL
Traffic chapter in the Configuration Guide for Local Traffic Management.
Importing keys and certificates
Once you have obtained a certificate, you can import this certificate into the
BIG-IP LTM system using the Configuration utility. By importing a
certificate or archive into the Configuration utility, you ease the task of
managing that certificate or archive. You can use the Import SSL
Certificates and Keys screen only when the certificate you are importing is
in Privacy Enhanced Mail (PEM) format.
To import a key or certificate
1. On the Main tab, expand Local Traffic.
2. Click SSL Certificates. The list of existing certificates displays.
Vedere la pagina 61
1 2 ... 57 58 59 60 61 62 63 64 65

Commenti su questo manuale

Nessun commento