Secure load balanced traffic by using SSL
SSL configuration task sequence
Enable SSL offload
Enable SSL by using the CLI
- enable ns feature SSL
- show ns feature
> enable ns feature ssl
Done
> show ns feature
Feature Acronym Status
------- ------- ------
1) Web Logging WL ON
2) SurgeProtection SP OFF
3) Load Balancing LB ON . . .
9) SSL Offloading SSL ON
10) Global Server Load Balancing GSLB ON . .
Done >
Enable SSL by using the GUI
-
In the navigation pane, expand System, and then click Settings.
-
In the details pane, under Modes and Features, click Change basic features.
-
Select the SSL Offloading check box, and then click OK.
-
In the Enable/Disable Feature(s)? message box, click Yes.
Create HTTP services
Add an HTTP service by using the CLI
- add service <name> (<IP> | <serverName>) <serviceType> <port>
- show service <name>
> add service SVC_HTTP1 10.102.29.18 HTTP 80
Done
> show service SVC_HTTP1
SVC_HTTP1 (10.102.29.18:80) - HTTP
State: UP
Last state change was at Wed Jul 15 06:13:05 2009
Time since last state change: 0 days, 00:00:15.350
Server Name: 10.102.29.18
Server ID : 0 Monitor Threshold : 0
Max Conn: 0 Max Req: 0 Max Bandwidth: 0 kbits
Use Source IP: NO
Client Keepalive(CKA): NO
Access Down Service: NO
TCP Buffering(TCPB): NO
HTTP Compression(CMP): YES
Idle timeout: Client: 180 sec Server: 360 sec
Client IP: DISABLED
Cacheable: NO
SC: OFF
SP: OFF
Down state flush: ENABLED
1) Monitor Name: tcp-default
State: UP Weight: 1
Probes: 4 Failed [Total: 0 Current: 0]
Last response: Success - TCP syn+ack received.
Response Time: N/A
Done
Add an HTTP service by using the GUI
-
Navigate to Traffic Management > SSL Offload > Services.
-
In the details pane, click Add.
-
In the Create Service dialog box, type the name of the service, IP address, and port (for example, SVC_HTTP1, 10.102.29.18, and 80).
-
In the Protocol list, select the type of the service (for example, HTTP).
-
Click Create, and then click Close. The HTTP service you configured appears in the Services page.
-
Verify that the parameters you configured are correctly configured by selecting the service and viewing the Details section at the bottom of the pane.
Add an SSL based virtual server
Add an SSL-based virtual server by using the CLI
- add lb vserver <name> <serviceType> [<IPAddress> <port>]
- show lb vserver <name>
> add lb vserver vserver-SSL-1 SSL 10.102.29.50 443
Done
> show lb vserver vserver-SSL-1
vserver-SSL-1 (10.102.29.50:443) - SSL Type: ADDRESS
State: DOWN[Certkey not bound] Last state change was at Tue Jun 16 06:33:08 2009 (+176 ms)
Time since last state change: 0 days, 00:03:44.120
Effective State: DOWN Client Idle Timeout: 180 sec
Down state flush: ENABLED
Disable Primary Vserver On Down : DISABLED
No. of Bound Services : 0 (Total) 0 (Active)
Configured Method: LEASTCONNECTION Mode: IP
Persistence: NONE
Vserver IP and Port insertion: OFF
Push: DISABLED Push VServer: Push Multi Clients: NO Push Label Rule: Done
Add an SSL-based virtual server by using the GUI
-
Navigate to Traffic Management > SSL Offload > Virtual Servers.
-
In the details pane, click Add.
-
In the Create Virtual Server (SSL Offload) dialog box, type the name of the virtual server, IP address, and port.
-
In the Protocol list, select the type of the virtual server, for example, SSL.
-
Click Create, and then click Close.
-
Verify that the parameters you configured are correctly configured by selecting the virtual server and viewing the Details section at the bottom of the pane. The virtual server is marked as DOWN because a certificate-key pair and services have not been bound to it.
Bind services to the SSL virtual server
Bind a service to a virtual server by using the CLI
- bind lb vserver <name> <serviceName>
- show lb vserver <name>
> bind lb vserver vserver-SSL-1 SVC_HTTP1
Done
> show lb vserver vserver-SSL-1 vserver-SSL-1 (10.102.29.50:443) - SSL Type:
ADDRESS State: DOWN[Certkey not bound]
Last state change was at Tue Jun 16 06:33:08 2009 (+174 ms)
Time since last state change: 0 days, 00:31:53.70
Effective State: DOWN Client Idle
Timeout: 180 sec
Down state flush: ENABLED Disable Primary Vserver On Down :
DISABLED No. of Bound Services : 1 (Total) 0 (Active)
Configured Method: LEASTCONNECTION Mode: IP Persistence: NONE Vserver IP and
Port insertion: OFF Push: DISABLED Push VServer: Push Multi Clients: NO Push Label Rule:
1) SVC_HTTP1 (10.102.29.18: 80) - HTTP
State: DOWN Weight: 1
Done
Bind a service to a virtual server by using the GUI
-
Navigate to Traffic Management > SSL Offload > Virtual Servers.
-
In the details pane, select a virtual server, and then click Open.
-
On the Services tab, in the Active column, select the check boxes next to the services that you want to bind to the selected virtual server.
-
Click OK.
-
Verify that the Number of Bound Services counter in the Details section at the bottom of the pane is incremented by the number of services that you bound to the virtual server.
Add a certificate-key pair
-
prime256v1 (P_256 on the ADC)
-
secp384r1 (P_384 on the ADC)
-
secp521r1 (P_521 on the ADC; supported on VPX only)
-
secp224r1 (P_224 on the ADC; supported on VPX only)
Add a certificate key pair by using the CLI
- add ssl certKey <certkeyName> -cert <string> [-key <string>]
- show sslcertkey <name>
> add ssl certKey CertKey-SSL-1 -cert ns-root.cert -key ns-root.key
Done
> show sslcertkey CertKey-SSL-1
Name: CertKey-SSL-1 Status: Valid,
Days to expiration:4811 Version: 3
Serial Number: 00 Signature Algorithm: md5WithRSAEncryption Issuer: C=US,ST=California,L=San
Jose,O=Citrix ANG,OU=NS Internal,CN=de fault
Validity Not Before: Oct 6 06:52:07 2006 GMT Not After : Aug 17 21:26:47 2022 GMT
Subject: C=US,ST=California,L=San Jose,O=Citrix ANG,OU=NS Internal,CN=d efault Public Key
Algorithm: rsaEncryption Public Key
size: 1024
Done
Add a certificate key pair by using the GUI
-
Navigate to Traffic Management > SSL > Certificates.
-
In the details pane, click Add.
-
In the Install Certificate dialog box, in the Certificate-Key Pair Name text box, type a name for the certificate key pair you want to add, for example, Certkey-SSL-1.
-
Under Details, in Certificate File Name, click Browse (Appliance) to locate the certificate. Both the certificate and the key are stored in the /nsconfig/ssl/ folder on the appliance. To use a certificate present on the local system, select Local.
-
Select the certificate you want to use, and then click Select.
-
In Private Key File Name, click Browse (Appliance) to locate the private key file. To use a private key present on the local system, select Local.
-
Select the key you want to use and click Select. To encrypt the key used in the certificate key pair, type the password to be used for encryption in the Password text box.
-
Click Install.
-
Double-click the certificate key pair and, in the Certificate Details window, verify that the parameters have been configured correctly and saved.
Bind an SSL certificate key pair to the virtual server
Bind an SSL certificate key pair to a virtual server by using the CLI
- bind ssl vserver <vServerName> -certkeyName <string>
- show ssl vserver <name>
> bind ssl vserver Vserver-SSL-1 -certkeyName CertKey-SSL-1
Done
> show ssl vserver Vserver-SSL-1
Advanced SSL configuration for VServer Vserver-SSL-1:
DH: DISABLED
Ephemeral RSA: ENABLED Refresh Count: 0
Session Reuse: ENABLED Timeout: 120 seconds
Cipher Redirect: ENABLED
SSLv2 Redirect: ENABLED
ClearText Port: 0
Client Auth: DISABLED
SSL Redirect: DISABLED
Non FIPS Ciphers: DISABLED
SSLv2: DISABLED SSLv3: ENABLED TLSv1: ENABLED
1) CertKey Name: CertKey-SSL-1 Server Certificate
1) Cipher Name: DEFAULT
Description: Predefined Cipher Alias
Done
Bind an SSL certificate key pair to a virtual server by using the GUI
-
Navigate to Traffic Management > SSL Offload > Virtual Servers.
-
Select the virtual server to which you want to bind the certificate key pair, for example, Vserver-SSL-1, and click Open.
-
In the Configure Virtual Server (SSL Offload) dialog box, on the SSL Settings tab, under Available, select the certificate key pair that you want to bind to the virtual server. Then click Add.
-
Click OK.
-
Verify that the certificate key pair that you selected appears in the Configured area.
Configure support for Outlook web access
https:// instead of http://.
-
Create an SSL action to enable OWA support.
-
Create an SSL policy.
-
Bind the policy to the SSL virtual server.
Create an SSL action to enable OWA support
Create an SSL action to enable OWA support by using the CLI
- add ssl action <name> -OWASupport ENABLED
- show SSL action <name>
> add ssl action Action-SSL-OWA -OWASupport enabled
Done
> show SSL action Action-SSL-OWA
Name: Action-SSL-OWA
Data Insertion Action: OWA
Support: ENABLED
Done
Create an SSL action to enable OWA support by using the GUI
-
Navigate to Traffic Management > SSL > Policies.
-
In the details pane, on the Actions tab, click Add.
-
In the Create SSL Action dialog box, in the Name text box, type Action-SSL-OWA.
-
Under Outlook Web Access, select Enabled.
-
Click Create, and then click Close.
-
Verify that Action-SSL-OWA appears in the SSL Actions page.
Create SSL policies
Create an SSL policy by using the CLI
- add ssl policy <name> -rule <expression> -reqAction <string>
- show ssl policy <name>
> add ssl policy-SSL-1 -rule ns_true -reqaction Action-SSL-OWA
Done
> show ssl policy-SSL-1
Name: Policy-SSL-1 Rule: ns_true
Action: Action-SSL-OWA Hits: 0
Policy is bound to following entities
1) PRIORITY : 0
Done
Create an SSL policy by using the GUI
-
Navigate to Traffic Management > SSL > Policies.
-
In the details pane, click Add.
-
In the Create SSL Policy dialog box, in the Name text box, type the name of the SSL Policy (for example, Policy-SSL-1).
-
In Request Action, select the configured SSL action that you want to associate with this policy (for example, Action-SSL-OWA). The ns_true general expression applies the policy to all successful SSL handshake traffic. However, to filter specific responses, you can create policies with a higher level of detail. For more information about configuring granular policy expressions, see SSL actions and policies.
-
In Named Expressions, choose the built-in general expression ns_true and click Add Expression. The expression ns_true now appears in the Expression text box.
-
Click Create, and then click Close.
-
Verify that the policy is correctly configured by selecting the policy and viewing the Details section at the bottom of the pane.
Bind the SSL policy to the SSL virtual server
Bind an SSL policy to an SSL virtual server by using the CLI
- bind ssl vserver <vServerName> -policyName <string>
- show ssl vserver <name>
> bind ssl vserver Vserver-SSL-1 -policyName Policy-SSL-1
Done
> show ssl vserver Vserver-SSL-1
Advanced SSL configuration for VServer Vserver-SSL-1:
DH: DISABLED
Ephemeral RSA: ENABLED
Refresh Count: 0
Session Reuse: ENABLED
Timeout: 120 seconds
Cipher Redirect: ENABLED
SSLv2 Redirect: ENABLED
ClearText Port: 0
Client Auth: DISABLED
SSL Redirect: DISABLED
Non FIPS Ciphers: DISABLED
SSLv2: DISABLED SSLv3: ENABLED TLSv1: ENABLED
1) CertKey Name: CertKey-SSL-1 Server Certificate
1) Policy Name: Policy-SSL-1 Priority: 0
1) Cipher Name: DEFAULT Description: Predefined Cipher Alias
Done
Bind an SSL policy to an SSL virtual server by using the GUI
-
Navigate to Traffic Management > SSL Offload > Virtual Servers.
-
In the details pane, select the virtual server (for example, Vserver-SSL-1), and then click Open.
-
In the Configure Virtual Server (SSL Offload) dialog box, click Insert Policy, and then select the policy that you want to bind to the SSL virtual server. Optionally, you can double-click the Priority field and type a new priority level.
-
Click OK.