Friday, February 21, 2020

Cisco ACE SSL termination

Hello,

do i need to add something else to make class class-default work?

policy-map multi-match VLAN220_POLICY_L4 class SHAREPOINT2013_CLASS_L4 loadbalance vip inservice loadbalance policy SHAREPOINT2013_POLICY_L7 loadbalance vip icmp-reply active loadbalance vip advertise active nat dynamic 17 vlan 220 appl-parameter http advanced-options HTTP_PARAMETER_MAP ssl-proxy server STAR_SSL_PSERVICE_SERVER class-map match-all SHAREPOINT2013_CLASS_L4 3 match virtual-address 192.168.220.54 tcp eq https policy-map type loadbalance first-match SHAREPOINT2013_POLICY_L7 class FORMS_CLASS_L7 serverfarm SHAREPOINT2019 ssl-proxy client SSL_SHAREPOINT_CLIENT class class-default serverfarm SHAREPOINT2013 ssl-proxy client SSL_SHAREPOINT_CLIENT class-map type http loadbalance match-all FORMS_CLASS_L7 2 match http header Host header-value "sp.mycompany.com" 3 match http url /forms/form1 

When I type sp.mycompany.com/forms/form1 I see page from serverfarm SHAREPOINT2019 as expected to FORMS_CLASS_L7 from SHAREPOINT2013_POLICY_L7. But if I type sp.mycompany.com or sp.mycompany.com/otherURI I didn't see page from serverfarm SHAREPOINT2013 as according to class class-default from SHAREPOINT2013_POLICY_L7.



No comments:

Post a Comment