cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
469
Views
0
Helpful
3
Replies

CSS SSL Transparent proxy + Back-end server config

nacho
Level 1
Level 1

Please have anybody a css1150x config which match with the scenario shown on page 8-4 that you can find in the following url:

http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_740/sslgd/examples.pdf

The only diference with my installatón is that we have only a SSL module. Except for this (only one ssl module) my scenario is the same. Our clients use multiple http connectons for shopping or browsing and e few SSL connection to make orders and pay.

We need cookie stickiness, because we can´t use other type of stickness (src-dest, ssl id, etc).

We need terminate ssl tunnels on the ssl module (client side) and also iniciate ssl tunnels (servers side)at the same time.

Thanks in advance

3 Replies 3

Gilles Dufour
Cisco Employee
Cisco Employee

the config would be exactly the same with just 1 module.

simply remove from the config all reference to ssl_module2.

Regards,

Gilles.

Please can you tell me if the attach configuration could work under the following premises:

- The same real servers are used for both http and https (192.168.178.20 and 192.168.178.21).

- We also use the same virtual ip for both http and https (192.168.168.73).

- We need that http traffic be balanced and passes transparently trought the CSS. Https traffic shoud be decripted balanced over backend servers and encryted again.

- Also we need that for the same client shopping the http and https sessions terminate on the same server. For this propose we implemente stickiness in base to arrow-point cookies, creates by the CSS.

Thans in advance

this looks good.

Gilles.