5-19
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 5 Configuring Virtual Servers
Configuring Virtual Servers
Assumption
A virtual server has been configured for HTTPS over TCP or Other over TCP in the Properties
configuration subset. For more information, see the “Configuring Virtual Server Properties” section on
page 5-10.
Procedure
Step 1 Choose Config > Virtual Contexts > context > Load Balancing > Virtual Servers. The Virtual
Servers table appears.
Step 2 Select the virtual server you want to configure for SSL termination, and then click Edit. The Virtual
Server configuration screen appears.
Step 3 Click SSL Termination. The Proxy Service Name field appears.
Step 4 In the Proxy Service Name field, select an existing SSL termination service, or select *New* to create
a new SSL proxy service:
• If you select an existing SSL service, the screen refreshes and allows you to view, modify, or
duplicate the existing configuration. See the “Shared Objects and Virtual Servers” section on
page 5-9 for more information about modifying shared objects.
• If you select *New*, the Proxy Service configuration subset appears.
Step 5 Configure the SSL service using the in Table 5-4.
For more information about SSL, see the “Configuring SSL” section on page 9-1.
Step 6 When you finish configuring virtual server properties, do the following:
• Click Deploy Now to deploy this configuration on the ACE appliance.
Table 5-4 Virtual Server SSL Termination Attributes
Field Description
Name Enter a name for this SSL proxy service. Valid entries are alphanumeric
strings with a maximum of 64 characters.
Keys Select the SSL key pair to use during the SSL handshake for data encryption.
Certificates Select the SSL certificate to use during the SSL handshake.
Chain Groups Select the chain group to use during the SSL handshake.
Auth Groups Select the SSL authentication group to associate with this proxy server
service.
CRL Best-Effort This option appears if you select an authentication group in the Auth Group
Name field.
Check the check box to allow the ACE to search client certificates for the
service to determine if it contains a CRL in the extension and retrieve the
value, if it exists.
Clear the check box to disable this feature.
CRL Name This option appears if the CRL Best-Effort check box is clear.
Select the Certificate Revocation List if the ACE is to use for this proxy
service.
Parameter Maps Select the SSL parameter map to associate with this proxy server service.
Comments to this Manuals