Bug ID 579525: Rewrite doesn't use CONNECT method for https proxy

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
11.4.1, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10

Opened: Mar 10, 2016

Severity: 3-Major

Symptoms

The rewrite plugin does not implement forwarding HTTPS requests through the HTTPS proxy correctly; however, forwarding HTTP requests through the HTTP proxy does work correctly.

Impact

Users are unable to connect to this resource

Conditions

APM portal access resource configured with https:// scheme

Workaround

To work around the problem, create a layered virtual server to catch HTTPS traffic leaving APM and forward it to a HTTPS proxy server using CONNECT. Proxy authentication is not implemented and if the response status from HTTPS proxy server is not 200, then use an iRule to close the connection

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips