<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LB works fine in ssl passthru but it does not work properly in ssl offload. in VMware NSX Discussions</title>
    <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/LB-works-fine-in-ssl-passthru-but-it-does-not-work-properly-in/m-p/1388263#M4799</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@&lt;STRONG style="font-size: 12.6px; font-family: proxima-nova, Arial, sans-serif; color: #666666;"&gt;&lt;A _jive_internal="true" data-avatarid="-1" data-userid="1680823" data-username="ddesmidt" href="https://communities.vmware.com/people/ddesmidt" name="&amp;amp;amp;lpos=apps_scodevmw : 83" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #3399cc; text-decoration: underline;"&gt;ddesmidt&lt;/A&gt;ddesmidt&lt;/STRONG&gt; you're outstanding!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Feb 2017 05:46:00 GMT</pubDate>
    <dc:creator>OptimalDesign</dc:creator>
    <dc:date>2017-02-17T05:46:00Z</dc:date>
    <item>
      <title>LB works fine in ssl passthru but it does not work properly in ssl offload.</title>
      <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/LB-works-fine-in-ssl-passthru-but-it-does-not-work-properly-in/m-p/1388261#M4797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Experts&lt;/P&gt;&lt;P&gt;I just test LB with web server pool and it works fine when LB works as Passthrough mode.&lt;/P&gt;&lt;P&gt;But it does not work at all when LB configured as SSL-offload... Welcome any technical advice!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) When I configured LB as a Passthrough mode, then it can be connected to web server and I've got log as below;&lt;/P&gt;&lt;P&gt;#show log follow&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;2017-02-16T10:55:38+00:00 NSX-edge-9-0 loadbalancer[12792]: [default]:&amp;nbsp; [local0.info] 192.168.110.10:58941 [16/Feb/2017:10:55:38.123] passthru1 Web-Tier-Pool-new/&lt;SPAN style="color: #ff0000;"&gt;web-03a&lt;/SPAN&gt; 1/0/38 1736 -- 1/1/1/0/0 0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;2017-02-16T10:55:38+00:00 NSX-edge-9-0 loadbalancer[12792]: [default]:&amp;nbsp; [local0.info] 192.168.110.10:58942 [16/Feb/2017:10:55:38.124] passthru1 Web-Tier-Pool-new/&lt;SPAN style="color: #0000ff;"&gt;web-02a&lt;/SPAN&gt; 1/1/42 1736 -- 0/0/0/0/0 0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;2017-02-16T10:55:38+00:00 NSX-edge-9-0 loadbalancer[12792]: [default]:&amp;nbsp; [local0.info] 192.168.110.10:58943 [16/Feb/2017:10:55:38.508] passthru1 Web-Tier-Pool-new/&lt;SPAN style="color: #ff0000;"&gt;web-03a&lt;/SPAN&gt; 1/1/15 1736 -- 0/0/0/0/0 0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;2017-02-16T10:55:38+00:00 NSX-edge-9-0 loadbalancer[12792]: [default]:&amp;nbsp; [local0.info] 192.168.110.10:58944 [16/Feb/2017:10:55:38.524] passthru1 Web-Tier-Pool-new/&lt;SPAN style="color: #0000ff;"&gt;web-02a&lt;/SPAN&gt; 1/0/78 4435 -- 0/0/0/0/0 0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) However, when I configure LB as SSL-offload, then it returns HTTP code 502 and "Bad Gateway" on the webpage.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;#show log follow&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;2017-02-16T10:32:27+00:00 NSX-edge-9-0 loadbalancer[1381]: [default]:&amp;nbsp; [local0.info] 192.168.110.10 - - [16/Feb/2017:10:32:27 +0000] "GET /cgi-bin/hol.cgi HTTP/1.1" &lt;SPAN style="color: #ff6600;"&gt;&lt;STRONG&gt;502&lt;/STRONG&gt;&lt;/SPAN&gt; 757 "" "" 58747 920 "LB_ssl_offload2_2~" "Web-Tier-Pool-new" "&lt;SPAN style="color: #ff0000;"&gt;web-03a&lt;/SPAN&gt;" 1 0 1 -1 4 PH-- 0 0 0 0 0 0 0 "" ""&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;2017-02-16T10:34:03+00:00 NSX-edge-9-0 loadbalancer[1381]: [default]:&amp;nbsp; [local0.info] 192.168.110.10 - - [16/Feb/2017:10:34:03 +0000] "GET /cgi-bin/hol.cgi HTTP/1.1" &lt;SPAN style="color: #ff6600;"&gt;&lt;STRONG&gt;502&lt;/STRONG&gt;&lt;/SPAN&gt; 766 "" "" 58762 400 "LB_ssl_offload2_2~" "Web-Tier-Pool-new" "&lt;SPAN style="color: #0000ff;"&gt;web-02a&lt;/SPAN&gt;" 2 0 1 -1 4 PH-- 0 0 0 0 0 0 0 "" ""&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;2017-02-16T10:43:37+00:00 NSX-edge-9-0 loadbalancer[1381]: [default]:&amp;nbsp; [local0.info] 192.168.110.10 - - [16/Feb/2017:10:43:37 +0000] "GET /cgi-bin/hol.cgi HTTP/1.1" &lt;SPAN style="color: #ff6600;"&gt;&lt;STRONG&gt;502&lt;/STRONG&gt;&lt;/SPAN&gt; 757 "" "" 58815 332 "LB_ssl_offload2_2~" "Web-Tier-Pool-new" "&lt;SPAN style="color: #ff0000;"&gt;web-03a&lt;/SPAN&gt;" 2 0 1 -1 5 PH-- 0 0 0 0 0 0 0 "" ""&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;2017-02-16T10:43:39+00:00 NSX-edge-9-0 loadbalancer[1381]: [default]:&amp;nbsp; [local0.info] 192.168.110.10 - - [16/Feb/2017:10:43:39 +0000] "GET /cgi-bin/hol.cgi HTTP/1.1" &lt;SPAN style="color: #ff6600;"&gt;&lt;STRONG&gt;502&lt;/STRONG&gt;&lt;/SPAN&gt; 766 "" "" 58819 698 "LB_ssl_offload2_2~" "Web-Tier-Pool-new" "&lt;SPAN style="color: #0000ff;"&gt;web-02a&lt;/SPAN&gt;" 2 0 1 -1 6 PH-- 0 0 0 0 0 0 0 "" ""&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;web-02a : 172.16.10.12/24 , GW 172.16.10.1/24 (vxlan 5000)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.6667px;"&gt;web-03a : 172.16.10.13/24 , GW 172.16.10.1/24 &lt;SPAN style="font-size: 10.6667px;"&gt;(vxlan 5000)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;LB : &lt;SPAN style="font-size: 10.6667px;"&gt;172.16.10.10/24 &lt;SPAN style="font-size: 10.6667px;"&gt;(vxlan 5000)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.6667px;"&gt;192.168.110.10 (My PC)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.6667px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.6667px;"&gt;Thanks alot!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.6667px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2017 11:10:10 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-NSX-Discussions/LB-works-fine-in-ssl-passthru-but-it-does-not-work-properly-in/m-p/1388261#M4797</guid>
      <dc:creator>OptimalDesign</dc:creator>
      <dc:date>2017-02-16T11:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: LB works fine in ssl passthru but it does not work properly in ssl offload.</title>
      <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/LB-works-fine-in-ssl-passthru-but-it-does-not-work-properly-in/m-p/1388262#M4798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you do "SSL-Passthrough" the clients terminate their HTTPS traffic on the pool members. So your Pool members are on https TCP 443.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you do "SSL-Offload" the clients terminate their HTTPS traffic on the Edge-LB and then Edge-LB talks to the Pool members on http TCP 80.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you do change your pool member configuration and healthchecks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dimitri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2017 11:14:13 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-NSX-Discussions/LB-works-fine-in-ssl-passthru-but-it-does-not-work-properly-in/m-p/1388262#M4798</guid>
      <dc:creator>ddesmidt</dc:creator>
      <dc:date>2017-02-16T11:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: LB works fine in ssl passthru but it does not work properly in ssl offload.</title>
      <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/LB-works-fine-in-ssl-passthru-but-it-does-not-work-properly-in/m-p/1388263#M4799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@&lt;STRONG style="font-size: 12.6px; font-family: proxima-nova, Arial, sans-serif; color: #666666;"&gt;&lt;A _jive_internal="true" data-avatarid="-1" data-userid="1680823" data-username="ddesmidt" href="https://communities.vmware.com/people/ddesmidt" name="&amp;amp;amp;lpos=apps_scodevmw : 83" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #3399cc; text-decoration: underline;"&gt;ddesmidt&lt;/A&gt;ddesmidt&lt;/STRONG&gt; you're outstanding!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Feb 2017 05:46:00 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-NSX-Discussions/LB-works-fine-in-ssl-passthru-but-it-does-not-work-properly-in/m-p/1388263#M4799</guid>
      <dc:creator>OptimalDesign</dc:creator>
      <dc:date>2017-02-17T05:46:00Z</dc:date>
    </item>
  </channel>
</rss>

