Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

SSL Termination not working in ACE

Hi,


The context was configured for Load Balancing Port 80 and 443 traffic before the SSL Configs was Applied.
The SSL Termination is configured on ACE module running the software version  A2(1.6a) [build 3.0(0)A2(1.6a)

The load balacing is working without no issues, But when i do a https://abc.www.abc.qa/wps/portal/login
the browser reconganizes the certificate from ACE, but does not show up any thing, just shows  this symbol € 
in a blank page.

Plese let me know if you have any suggestions.

Thanks in Advance.


Here is the relevant config.
===================

crypto csr-params ABC-II-PRAMS
  country XX
  state XXXX
  locality XXXX
  organization-name abc council
  common-name abc.www.abc.qa
  serial-number 1
  email abc@abc.com


rserver host abcserver1
  ip address 10.14.1.165
  inservice
rserver host abcserver2
  ip address 10.14.1.177
  inservice


ssl-proxy service abc.www.proxy
  key abc-II-key.pem
  cert abc-II-cert.pem


serverfarm host abc.www.abc.qa-443
  failaction purge
  rserver abcserver1
    probe abcicmp
    inservice
  rserver abcserver2
    probe abcicmp
    inservice
serverfarm host abc.www.abc.qa-80
  failaction purge
  rserver abcserver1
    probe abcicmp
    inservice
  rserver abcserver2
    probe abcicmp
    inservice

sticky ip-netmask 255.255.255.255 address source abc.www.abc.qa-sticky-80
timeout 120
serverfarm abc.www.abc.qa-80

sticky ip-netmask 255.255.255.255 address source abc.www.abc.qa-sticky-443
timeout 120
serverfarm abc.www.abc.qa-443
!
!
class-map match-all abc.www.abc.qa-443
match virtual-address 10.14.1.203 tcp eq https
!
class-map match-all abc.www.abc.qa-80
match virtual-address 10.14.1.203 tcp eq www
!
!
policy-map type loadbalance first-match abc.www.abc.qa-VIP-443
class class-default
sticky-serverfarm abc.www.abc.qa-sticky-443
!
policy-map type loadbalance first-match abc.www.abc.qa-VIP-80
class class-default
sticky-serverfarm abc.www.abc.qa-sticky-80


policy-map multi-match abc-POLICY


class abc.www.abc.qa-80
    loadbalance vip inservice
    loadbalance policy abc.www.abc.qa-VIP-80
    loadbalance vip icmp-reply

  class abc.www.abc.qa-443
    loadbalance vip inservice
    loadbalance policy abc.www.abc.qa-VIP-443
    loadbalance vip icmp-reply
    ssl-proxy server abc.www.proxy

=============================

Everyone's tags (1)
1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: SSL Termination not working in ACE

Hi,

You may want to check this thread I think it would be very helpful.

https://supportforums.cisco.com/thread/2027253

HTH

__ __

Pablo

Cisco TAC

2 REPLIES
Cisco Employee

Re: SSL Termination not working in ACE

Hi,

You may want to check this thread I think it would be very helpful.

https://supportforums.cisco.com/thread/2027253

HTH

__ __

Pablo

Cisco TAC

New Member

Re: SSL Termination not working in ACE

Hi,

It is working now, adding port 80 fixed  the issue.

Many Thanks.  5/5

623
Views
0
Helpful
2
Replies
CreatePlease to create content