<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL &amp; URL Problem in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238658#M3398</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With SSL traffic, the CSS cannot see the URL.  The only systems that can see the URL are the SSL server and the SSL client.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With that in mind, the only things we can load balance SSL on is the TCP port and IP address.  Any layer 5 information is encrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Apr 2004 18:29:40 GMT</pubDate>
    <dc:creator>stevehall</dc:creator>
    <dc:date>2004-04-06T18:29:40Z</dc:date>
    <item>
      <title>SSL &amp; URL Problem</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238657#M3397</link>
      <description>&lt;P&gt;I have a customer who requires client access to specific SSL / https content on different servers using different TCP port numbers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using standard http we used the 'url' command in the content rules as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;url "/scripts/wgate/webgui_TST*"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, when we try this in a content rule using SSL it doesn't work as (I presume) the SSL Hello never gets responded to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen a few messages already posted highlighting this problem..  Does anyone have any suggestions on workaround options..?  Is there a way to redirect SSL / https traffic.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My contnent rule for standard http looks as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  content standard-http&lt;/P&gt;&lt;P&gt;    add service sss02-83&lt;/P&gt;&lt;P&gt;    add service sss03-83&lt;/P&gt;&lt;P&gt;    vip address xxx.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;    balance aca&lt;/P&gt;&lt;P&gt;    protocol tcp&lt;/P&gt;&lt;P&gt;    port 80&lt;/P&gt;&lt;P&gt;    url "/scrs/wate/webgui_STS*"&lt;/P&gt;&lt;P&gt;    advanced-balance arrowpoint-cookie&lt;/P&gt;&lt;P&gt;    active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to do the same but using SSL..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers....J Pepper&lt;/P&gt;&lt;P&gt;EDS&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2004 12:57:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238657#M3397</guid>
      <dc:creator>john.pepper</dc:creator>
      <dc:date>2004-04-06T12:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSL &amp; URL Problem</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238658#M3398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With SSL traffic, the CSS cannot see the URL.  The only systems that can see the URL are the SSL server and the SSL client.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With that in mind, the only things we can load balance SSL on is the TCP port and IP address.  Any layer 5 information is encrypted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2004 18:29:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238658#M3398</guid>
      <dc:creator>stevehall</dc:creator>
      <dc:date>2004-04-06T18:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: SSL &amp; URL Problem</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238659#M3399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;to complete Steve answer, you can alsu use an SSL offloader to decrypt the traffic for the CSS so the CSS can see the url and http header.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CSS11500 can receive an ssl module to do the ssl encryption/decryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also use a SCA as an external SSL offloader.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Apr 2004 11:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238659#M3399</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2004-04-07T11:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: SSL &amp; URL Problem</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238660#M3400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We did come up with a workaround using the 'redirect' command in the main http Contnet Rules. This 'redirected' user traffic to a different url which in turn pointed at a Contnet Rule / VIP configured for SSL. This means users only ever had to remember specific business http url's&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An extract from our test config is shown below.  It seems to work ok.  Do you see this as a valid configuration.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;content abc-http&lt;/P&gt;&lt;P&gt;    vip address 192.168.1.100&lt;/P&gt;&lt;P&gt;    balance aca&lt;/P&gt;&lt;P&gt;    protocol tcp&lt;/P&gt;&lt;P&gt;    port 80&lt;/P&gt;&lt;P&gt;    url "/scs/ate/gui_TST*"&lt;/P&gt;&lt;P&gt;    advanced-balance arrowpoint-cookie&lt;/P&gt;&lt;P&gt;redirect "&lt;A class="jive-link-custom" href="https://wwwtst.tst.zero.com/scs/ate/gui_TST/" target="_blank"&gt;https://wwwtst.tst.zero.com/scs/ate/gui_TST/&lt;/A&gt;!"&lt;/P&gt;&lt;P&gt;active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;content ssl-abc&lt;/P&gt;&lt;P&gt;    add service ssl-as02-ts-port-1443&lt;/P&gt;&lt;P&gt;    add service ssl-as03-ts-port-1443&lt;/P&gt;&lt;P&gt;    advanced-balance ssl&lt;/P&gt;&lt;P&gt;    application ssl&lt;/P&gt;&lt;P&gt;    balance aca&lt;/P&gt;&lt;P&gt;    vip address 192.168.1.101&lt;/P&gt;&lt;P&gt;    protocol tcp&lt;/P&gt;&lt;P&gt;    port 443&lt;/P&gt;&lt;P&gt;    url "/*"&lt;/P&gt;&lt;P&gt;    active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers...John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Apr 2004 11:41:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238660#M3400</guid>
      <dc:creator>john.pepper</dc:creator>
      <dc:date>2004-04-07T11:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: SSL &amp; URL Problem</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238661#M3401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That config is valid.  You just need to make sure all the SSL (HTTPS) links have the proper host name that resolves to the .101 address.  Also, make sure the SSL cert has a "cn" field with the proper domain name.  If it does not match, then the user will get a warning message on the browser stating the domain names don't match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Apr 2004 18:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238661#M3401</guid>
      <dc:creator>stevehall</dc:creator>
      <dc:date>2004-04-07T18:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSL &amp; URL Problem</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238662#M3402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Steve / Giles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the responses, much appreciated and helpful information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers...John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Apr 2004 18:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-url-problem/m-p/238662#M3402</guid>
      <dc:creator>john.pepper</dc:creator>
      <dc:date>2004-04-07T18:41:25Z</dc:date>
    </item>
  </channel>
</rss>

