cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
465
Views
0
Helpful
3
Replies

CSS SSL Transparent proxy + Back-end server config

nacho
Level 1
Level 1

Please have anybody a css1150x config which match with the scenario shown on page 8-4 that you can find in the following url:

http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_740/sslgd/examples.pdf

The only diference with my installatón is that we have only a SSL module. Except for this (only one ssl module) my scenario is the same. Our clients use multiple http connectons for shopping or browsing and e few SSL connection to make orders and pay.

We need cookie stickiness, because we can´t use other type of stickness (src-dest, ssl id, etc).

We need terminate ssl tunnels on the ssl module (client side) and also iniciate ssl tunnels (servers side)at the same time.

Thanks in advance

3 Replies 3

Gilles Dufour
Cisco Employee
Cisco Employee

the config would be exactly the same with just 1 module.

simply remove from the config all reference to ssl_module2.

Regards,

Gilles.

Please can you tell me if the attach configuration could work under the following premises:

- The same real servers are used for both http and https (192.168.178.20 and 192.168.178.21).

- We also use the same virtual ip for both http and https (192.168.168.73).

- We need that http traffic be balanced and passes transparently trought the CSS. Https traffic shoud be decripted balanced over backend servers and encryted again.

- Also we need that for the same client shopping the http and https sessions terminate on the same server. For this propose we implemente stickiness in base to arrow-point cookies, creates by the CSS.

Thans in advance

this looks good.

Gilles.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: