cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1432
Views
0
Helpful
2
Replies

Cisco ACE 20 SSL termination HTTP HTTPS

Hi,

I have configured ACE such way when  Clients will establish a connection using HTTPS (SSL) to the virtual IP address (VIP) configured
on the Cisco ACE.HTTPS causes the client’s TCP session to be encrypted between the browser and the ACE. Once the session reaches the ACE,

the ACE will decrypt the session and forward it to a real server in clear text (HTTP).

I used self signed certificate installed in ACE for this purpose.

Note that Servers have certificate signed by CA.

Everything works fine but when I hit VIP then browser says following:


"The security certificate presented by this website was not issued by a trusted certificate authority.
The security certificate presented by this website was issued for a different website's address.
Security certificate problems may indicate an attempt to trick you or intercept any data you send to the server."


Depending on different browser prompt when I click unblock or show all content then it goes to actual display page, but after putting

credentials it says "Incorrect Login Details"

I have installed this self signed cert to browser and try but no luck

I believe it should work with self signed installed in ACE...

Is there any way to disable server authentication from ACE side

Anyone have ideas to workarround this problem?

 

Thanks ,

Munim.

2 Replies 2

dlance
Level 1
Level 1

If the ACE is serving internet web pages it must have a real certificate loaded for SSL termination.

For internal use self signed is ok.

Just have the internal users ignore the certificate warning.

 

Hi,

 

Thanks for Your mail.

After Ignoring certificate warning , Different browser shows different message like unsecure contents blocked by the browser “‘This page includes script from unauthenticated sources’. After ignoring all/unblock everything when the login prompt come then putting credentials says

We have 2 server in the serverfarm. Both canbe accessed individually but when accessing with VIP

it will not serving.

Any ideas?

 

Regards,

Munim.