Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

F5 Networks F5CAB5 Exam - Topic 7 Question 10 Discussion

Refer to the exhibit.A BIG-IP Administrator needs to deploy an application on the BIG-IP system to performSSL offload and re-encrypt the traffic to pool members. During testing, users are unable to connect to the application.What must the BIG-IP Administrator do to resolve the issue? (Choose one answer)
D) Configure an SSL Profile (Server)
A) Remove the configured SSL Profile (Client)
B) Configure Protocol Profile (Server) as splitsession-default-tcp
C) Enable Forward Proxy in the SSL Profile (Client)

F5 Networks F5CAB5 Exam - Topic 7 Question 10 Discussion

Actual exam question for F5 Networks's F5CAB5 exam
Question #: 10
Topic #: 7
[All F5CAB5 Questions]

Refer to the exhibit.

A BIG-IP Administrator needs to deploy an application on the BIG-IP system to performSSL offload and re-encrypt the traffic to pool members. During testing, users are unable to connect to the application.

What must the BIG-IP Administrator do to resolve the issue? (Choose one answer)

Show Suggested Answer Hide Answer
Suggested Answer: D

To successfully performSSL offload and re-encryptionon a BIG-IP system, the virtual server must be configured withboth a Client SSL profile and a Server SSL profile. The Client SSL profile enables BIG-IP to decrypt inbound HTTPS traffic from clients, while the Server SSL profile is required tore-encrypt traffic before forwarding it to the pool members.

From the exhibit, the virtual server has aClient SSL profile configured, which allows BIG-IP to accept HTTPS connections from clients. However, there isno Server SSL profile attached, meaning BIG-IP attempts to sendunencrypted HTTP trafficto pool members listening on HTTPS (port 443). This protocol mismatch causes the server-side SSL handshake to fail, resulting in users being unable to connect to the application.

This behavior is well documented in BIG-IP SSL troubleshooting guides: when backend servers expect HTTPS, a Server SSL profile is mandatory to establish a secure connection from BIG-IP to the pool members.

The other options are incorrect:

Removing the Client SSL profile (Option A) would break client-side HTTPS.

The server-side TCP profile (Option B) is unrelated to SSL encryption.

Forward Proxy (Option C) is only used for outbound SSL inspection scenarios.

Therefore, configuring anSSL Profile (Server)is the correct and required solution.


Contribute your Thoughts:

0/2000 characters
Sharmaine
4 hours ago
But what about option C? Enabling Forward Proxy could help too.
upvoted 0 times
...
Layla
5 days ago
I agree, without it, users can't connect. It's essential for secure traffic.
upvoted 0 times
...
Laura
11 days ago
I think option D is the best choice. An SSL Profile (Server) is crucial for re-encryption.
upvoted 0 times
...
Felton
16 days ago
Option A seems risky. Removing the SSL Profile could cause more problems.
upvoted 0 times
...
Giuseppe
21 days ago
I lean towards option B. The Protocol Profile might fix session issues.
upvoted 0 times
...
Dannette
26 days ago
True, but I feel like the SSL Profile (Server) is more fundamental.
upvoted 0 times
...
Gennie
1 month ago
But what about option C? Enabling Forward Proxy could help too.
upvoted 0 times
...
Ira
1 month ago
I agree, without it, users can't connect. It's essential for secure traffic.
upvoted 0 times
...
Edmond
1 month ago
I think option D is the best choice. An SSL Profile (Server) is crucial for re-encryption.
upvoted 0 times
...
Lenny
2 months ago
I'm surprised they didn't check the SSL settings first!
upvoted 0 times
...
Katina
2 months ago
Wait, why would they use splitsession-default-tcp? Sounds odd.
upvoted 0 times
...
Jutta
2 months ago
Removing the SSL Profile? That sounds risky.
upvoted 0 times
...
Dan
2 months ago
I think enabling Forward Proxy is the way to go!
upvoted 0 times
...
Daniel
2 months ago
They need to configure an SSL Profile (Server) for sure.
upvoted 0 times
...
Carissa
2 months ago
I’m a bit confused about the Protocol Profile option; I don’t recall it being a common solution for SSL issues.
upvoted 0 times
...
Barbra
4 months ago
This question seems similar to one we practiced where we had to configure profiles correctly. I wonder if the SSL Profile (Server) is the key here.
upvoted 0 times
...
Barabara
4 months ago
I'm not entirely sure, but I feel like enabling Forward Proxy in the SSL Profile might be related to how traffic is managed.
upvoted 0 times
...
Rickie
4 months ago
I think I remember something about needing an SSL Profile for the server to handle the re-encryption properly.
upvoted 0 times
...

Save Cancel