7-17
User
Guide

for

the

Cisco

Application

Networking

Manager

5.2
OL-26572-01
Chapter
7






Configuring

Virtual

Servers
Configuring
Virtual

Servers


Configuring
Virtual

Server
SSL
Termination,

page
7-17
Configuring
Virtual

Server

SSL

Termination
You
can

configure

virtual

server

SSL

termination

service,

which

allows

the

virtual

server

to

act

as

an
SSL
proxy

server

and

terminate

SSL

sessions

between

it

and

its

clients.
Assumption
Make
sure

t

hat

a

vi

rtual

server

has

been

configured

for

HTTPS

over

TCP

or

Ot

her

over

TCP

i

n

th

e
Properties
configuration

subset.

For

more

information,

see

the

“Configuring

Virtual

Server

Properties”
section
on

page

7-11 .
Procedure
Step
1
Choose
Config
>

Devices

>

context

>

Load

Balancing

>

Virtual

Servers.
The
Virtual

Servers

table

appears.
Step
2
In
the

Virtual

Servers

table,

choose

the

virtual
server
that
you

want

to

configure

for

SSL

termination,
and
cl

ick

Edit.
The
Virtual

Server

configuration

window

appears.
Step
3
In
the

Virtual

Server

configuration

window,

click
SSL
Termination.
The
Proxy

Service

Name

field

appears.
Step
4
In
the

Proxy

Service

Name

field,

choose

an

existing

SSL

termination

service,

or

choose
*New*
to

create
a
new

SSL

proxy

service,

and

do

one


of

the

following:


If
you

chose

an

existing

SSL

service,

the
window

refreshes

and

allows

you

to

view,

modify,

or
duplicate
the

existing

configuration.

See

the

“Shared

Objects

and

Virtual

Servers”

section

on
page
7-9

for


more

information

about

modifying

shared

objects.


If
you

chose
*New*,
t

he
Proxy
Service

configuration
subset
appears.
Step
5
Configure
the

SSL

service

using

the

information
in
Ta
b

l

e
7-5
.
For
more

information

about

SSL,

see

the

“Configuring

SSL”

section

on

page

11-1 .
Ta
b

l

e


7-5
Virtual
Server

SSL

Attributes
Field
Description
Name
Name
for

this

SSL

proxy

service.

Valid

entries

are

alphanumeric

strings

with

a

maximum

of

26
characters.
Keys
SSL
key

pair

to

use

during

the

SSL

handshake

for

data

encryption.
Certificates
SSL
certificate

to

use

during

the

SSL

handshake.
Chain
Groups
Chain
group

to

use

during

the

SSL

handshake.
Auth
Groups
SSL
authentication

group

to

associate

with

this

proxy

server

service.
CRL
Best-Effort
Option
that

appears

if

you

chose

an

authentication

group

in

the

Auth

Groups

field.
Check
the

check

box

to

allow

the

ANM

to

search

client

certificates

for

the

service

to

determine

if
it
contains

a

CRL

in

the

extension

and

retrieve

the

value,

if

it

exists.
Uncheck
the

check

box

to

disable

this

feature.