Load Balancing with a CSM & SSL Module

Unanswered Question
Apr 21st, 2009

I'm trying to understand the best way to balance traffic to two servers when decrypting and re-encrypting with the CSM and an SSL module. I take the SSL traffic hitting the first CSM VIP and forward to the SSL module for decryption. Send the decrypted traffic back to another VIP on the CSM. Send the traffic to the client proxy VIP on the SSL which encrypts the traffic and forwards to the CSM VIP. That final VIP passes the traffic to the serverfarm containing the actual servers. How do I make sure the traffic is balanced between the final VIP and my servers. It seems that sticking on SSL session ID is the only way to go at that point which made decryption pointless. I feel like I'm missing something basic here.


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
sachinga.hcl Mon, 06/01/2009 - 10:19

Hi David,

Here find some full config example for your perusal for CSM and SSL Services Module Initial Configuration Example


2nd config example to Configuring CSM to Load Balance SSL to a Farm of SCAs for One-Armed Proxy Mode


Sachin garg

carlsond Mon, 06/01/2009 - 10:39

I had read through these and found my issue. It was the balancing between the two SSL mods that I needed to work through and then an application issue got in the way.



This Discussion