Specifying A Virtual Port - Cisco 11503 - CSS Content Services Switch Configuration Manual

Content services switch ssl configuration guide
Hide thumbs Also See for 11503 - CSS Content Services Switch:
Table of Contents

Advertisement

Chapter 4
Configuring SSL Termination

Specifying a Virtual Port

OL-5655-01
If the VIP address has not been defined for the virtual SSL sever when you
activate the SSL proxy list (see the
Connections"
section), the CSS logs an error message and does not activate the
SSL proxy list. When you activate a content rule with a configured SSL service,
the CSS verifies that each VIP address configured in the content rule matches at
least one VIP address configured in the SSL proxy list in each of the added
services. If a match is not found, the CSS logs an error message and does not
activate the content rule.
For example, to specify a VIP address for the virtual SSL server that corresponds
to a VIP address configured in a content rule, enter:
(config-ssl-proxy-list[ssl_list1])# ssl-server 20 vip address
192.168.3.6
To remove a VIP address from a specific virtual SSL server, enter:
(config-ssl-proxy-list[ssl_list1])# no ssl-server 20 vip address
The SSL module uses the virtual port to know which traffic it should accept. Use
the ssl-server number port number command to specify a virtual TCP port
number for the virtual SSL server. Enter a TCP port number that corresponds with
an SSL content rule, which uses the specified TCP port number.
Specify a port number from 1 to 65535. The default port is 443. Ensure that the
specified port number matches the port configured in a content rule (see the
"Configuring a Content Rule for SSL Termination"
If the virtual port has not been defined for the virtual SSL server when you
activate the SSL proxy list (see the
Connections"
section), the CSS logs an error message and does not activate the
SSL proxy list. When you activate a content rule with a configured SSL service,
the CSS verifies that each virtual port configured in the content rule matches at
least one port configured in the SSL proxy list in each of the added services. If a
match is not found, the CSS logs an error message and does not activate the
content rule.
For example, to specify a virtual port of 444, enter:
(config-ssl-proxy-list[ssl_list1])# ssl-server 20 port 444
Configuring Virtual SSL Servers for an SSL Proxy List
"Specifying the Nagle Algorithm for SSL TCP
"Specifying the Nagle Algorithm for SSL TCP
Cisco Content Services Switch SSL Configuration Guide
section).
4-7

Advertisement

Table of Contents
loading

This manual is also suitable for:

11500 series

Table of Contents