Re: [Alteon] problem with sslid and sticky session

Ali Abbas <[email protected]> Fri, 5 Feb 2010 22:59:27 +0100
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <[email protected]>
--===============0676983231==
Content-Type: multipart/alternative; boundary=0015173ff8cee44be9047ee191c4

--0015173ff8cee44be9047ee191c4
Content-Type: text/plain; charset=ISO-8859-1

Hi Travis

On Fri, Feb 5, 2010 at 10:17 PM, Gamble, Travis <
[email protected]> wrote:

>  I know in some versions of IE, it regenerates the SSL ID every 2 minutes
> which would effectively break this functionality.
>
> Without looking at a bunch of sniffs, I'm not sure if that functionality is
> still true on recent versions, but if so, you may be stuck with source IP as
> your session persistence method.
>
>

Don't forget, ISPs often proxies http and https through different proxies,
so you are going hit a wall here with pbind clientip

Best bet, use pbind cookie  and use an ssl offloader since the stream will
be encrypted, thus the application will not be able to see the cookie.

Regards

--
Ali Abbas
Blog: http://alouche.net

--0015173ff8cee44be9047ee191c4
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hi Travis<br><br><div class=3D"gmail_quote">On Fri, Feb 5, 2010 at 10:17 PM=
, Gamble, Travis <span dir=3D"ltr">&lt;<a href=3D"mailto:Travis.Gamble@fras=
erhealth.ca">[email protected]</a>&gt;</span> wrote:<br><blockq=
uote class=3D"gmail_quote" style=3D"border-left: 1px solid rgb(204, 204, 20=
4); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">





<div>
<div dir=3D"ltr" align=3D"left"><span><font face=3D"Arial" size=3D"2" color=
=3D"#0000ff">I know in some versions of IE, it regenerates the SSL ID=20
every 2 minutes which would effectively break this=20
functionality.</font></span></div>
<div dir=3D"ltr" align=3D"left"><span><font face=3D"Arial" size=3D"2" color=
=3D"#0000ff"></font></span>=A0</div>
<div dir=3D"ltr" align=3D"left"><span><font face=3D"Arial" size=3D"2" color=
=3D"#0000ff">Without looking at a bunch of sniffs, I&#39;m not sure if that=
=20
functionality is still true on recent versions, but if so, you may be stuck=
 with=20
source IP as your session persistence method.</font></span></div>
<div dir=3D"ltr" align=3D"left"><span><font face=3D"Arial" size=3D"2" color=
=3D"#0000ff"></font></span>=A0</div></div></blockquote><div><br>Don&#39;t f=
orget, ISPs often proxies http and https through different proxies, so you =
are going hit a wall here with pbind clientip<br>

<br>Best bet, use pbind cookie=A0 and use an ssl offloader since the stream=
 will be encrypted, thus the application will not be able to see the cookie=
.<br><br>Regards<br><br clear=3D"all">--<br>Ali Abbas<br>Blog: <a href=3D"h=
ttp://alouche.net">http://alouche.net</a>=A0
<br></div></div>

--0015173ff8cee44be9047ee191c4--

--===============0676983231==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

--===============0676983231==--