Configuring HTTPS reverse proxy on multiple HTTPS domains
search cancel

Configuring HTTPS reverse proxy on multiple HTTPS domains

book

Article ID: 166033

calendar_today

Updated On:

Products

Advanced Secure Gateway Software - ASG ProxySG Software - SGOS

Issue/Introduction

This FAQ further describes the requirements and steps to create multiple HTTPS domains as HTTPS reverse proxy.

Resolution

After the first HTTPS keyring is assigned to an HTTPS Reverse Proxy service on the ProxySG or Advanced Secure Gateway (ASG), and working successfully, you will be required to create another HTTPS Reverse Proxy Service on the ProxySG or ASG in order to differentiate it from the first one.

Either a different IP address (or VIP) is required, or a different destination port, which in this case might be port 443 or 444.

With each additional backend HTTPS server host, you are required to create additional VIPs and Keyrings on the proxy.

Creating a VIP

From the Management Console, select Configuration > Network > Advanced > VIPs

Note: VIP must be routable within the same subnet of the physical IP of the proxy

Creating an Additional HTTPS Reverse Proxy Service

This enables the proxy to intercept the respective traffic and forward it to the correct HTTPS server host.

  1. From the Management Console, select Proxy Services > HTTPS Reverse Proxy Services > Proxy settings
  2. Set the Keyring as your design for the respective HTTPS domain
  3. Set other attributes as necessary
  4. Select the Proxy Services > HTTPS Reverse Proxy Services > Listener tab
  5. Set the Destination host as the VIP (configured previously) of the ProxySG or ASG

Create the forwarding rule

  1. Create forwarding hosts for the subsequent HTTPS domain hosts
  2. Allow access to the subsequent HTTPS domains
  3. Create and define the forwarding rule for the subsequent HTTPS domains

For detailed instructions see Reverse Proxy with SSL