SSL communication is terminated at Load Balancer 1. The request is then re-encrypted and securely forwarded to the SSL port of the Directory Server user data instance. Load Balancer 1 also encrypts the responses it receives back from the user data instance, and sends these encrypted responses back to the client. Towards this end create an SSL proxy for SSL termination and regeneration.
You should have a root certificate issued by a recognized CA.
Access https://is-f5.example.com, the BIG-IP load balancer login page, in a web browser.
Log in with the following information.
username
password
Click Configure your BIG-IP (R) using the Configuration Utility.
In the left pane, click Proxies.
Under the Proxies tab, click Add.
In the Add Proxy dialog, provide the following information.
Check the SSL and ServerSSL checkbox.
The IP address of Load Balancer 1.
489
The secure port number
The IP address of Load Balancer 1.
490
The non-secure port number
Choose Local Virtual Server.
Choose lb-1.example.com.
Choose lb-1.example.com.
Check this checkbox.
Click Next.
On the page starting with “Insert HTTP Header String,” change to Rewrite Redirects and choose Matching.
Click Next.
On the page starting with “Client Cipher List String”, accept the defaults.
Click Next.
On the page starting with “Server Chain File,” change to Server Trusted CA's File and select “OpenSSL_CA_Cert.crt” from the drop-down list.
Click Done.
The new proxy server is added to the Proxy Server list.
Log out of the load balancer console.