Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

F5 Networks F5CAB3 Exam - Topic 1 Question 6 Discussion

Actual exam question for F5 Networks's F5CAB3 exam
Question #: 6
Topic #: 1
[All F5CAB3 Questions]

The BIG-IP Administrator has to provide encrypted communication between the users and the virtual server they access. Multiple hostnames are configured in DNS with the same IP address. Which profile type and setting in the profile should be used? (Choose one answer)

Show Suggested Answer Hide Answer
Suggested Answer: C

To provide encrypted communication between users and a virtual server, the BIG-IP system acts as a transparent SSL/TLS proxy. The administrative configuration required for this is a Client SSL profile.

When multiple hostnames (FQDNs) are associated with a single IP address, the system must determine which SSL certificate to present to the client during the initial TLS handshake. This is achieved using an extension of the TLS protocol called Server Name Indication (SNI).

The configuration logic is as follows:

Profile Type: The Client SSL profile is responsible for terminating the SSL connection from the client (the user) to the BIG-IP system.

The Setting: Within the Client SSL profile (under the 'Advanced' view), there is a field specifically called Server Name. By entering the specific hostname (e.g., www.example.com) in this field, the BIG-IP system can match the hostname requested by the client in the ClientHello message to the correct profile.

Implementation: The administrator typically creates multiple Client SSL profiles---one for each hostname---and assigns them all to the same virtual server. One of these profiles must be designated as the Default SSL Profile for SNI to handle requests where the client does not provide a hostname or provides one that does not match any specific profile.

By using the Client SSL profile and the Server Name setting, the BIG-IP system ensures that each user receives the correct certificate for the specific site they are trying to reach, even though all sites share a single virtual server IP.


Contribute your Thoughts:

0/2000 characters
Shakira
15 hours ago
Agreed with A! It's the best choice for multiple hostnames.
upvoted 0 times
...
Dorothy
6 days ago
Wait, why would you use Server SSL for this? Seems off.
upvoted 0 times
...
Nidia
11 days ago
I think it's actually C) Client SSL, Server Name.
upvoted 0 times
...
Ludivina
16 days ago
Definitely A) Client SSL, Client Name. Makes sense!
upvoted 0 times
...
Rozella
21 days ago
I believe the answer is A) Client SSL, Client Name, because it seems to match the requirement for user connections, but I might need to double-check my notes on this.
upvoted 0 times
...
Shelia
26 days ago
I’m a bit confused about the difference between Client SSL and Server SSL in this context. I feel like I should lean towards Client SSL, but I can't recall the exact setting we discussed.
upvoted 0 times
...
Casie
1 month ago
I remember practicing a similar question where we had to choose between Client and Server SSL profiles. I think the Client Name option might be relevant here, but I could be wrong.
upvoted 0 times
...
Colette
1 month ago
I think we need to use the Client SSL profile since it handles the encryption for users connecting to the virtual server, but I'm not sure about the hostname setting.
upvoted 0 times
...

Save Cancel