Comprehensive data protection for all workloads
Post Reply
dgapinski
Enthusiast
Posts: 62
Liked: 4 times
Joined: Dec 05, 2013 8:09 pm
Full Name: Dan Gapinski
Contact:

Reverse proxy SSL connections for vLab

Post by dgapinski »

Hello,

It looks like the Veeam vLab appliance is awesome at presenting insecure connections, but cannot reverse proxy an SSL connection for the purpose of allowing some web server testing. Has anyone had success with using a free Kemp for this purpose? It would mean that the subnets on both Kemp vNICs would be the same, unless I introduce some extra routing to appease what I bet would be a rather inflexible configuration in that regard. Thanks for your thoughts!

Thanks,
Dan
dellock6
VeeaMVP
Posts: 6139
Liked: 1932 times
Joined: Jul 26, 2009 3:39 pm
Full Name: Luca Dell'Oca
Location: Varese, Italy
Contact:

Re: Reverse proxy SSL connections for vLab

Post by dellock6 »

The vlab appliance should just re-route the port you configure, what is the error message you are seeing?
Or simply the connection times out?
Luca Dell'Oca
Principal EMEA Cloud Architect @ Veeam Software

@dellock6
https://www.virtualtothecore.com/
vExpert 2011 -> 2022
Veeam VMCE #1
dgapinski
Enthusiast
Posts: 62
Liked: 4 times
Joined: Dec 05, 2013 8:09 pm
Full Name: Dan Gapinski
Contact:

Re: Reverse proxy SSL connections for vLab

Post by dgapinski »

Yes you are correct, it will re-route the port, but won't do any cert handling, hence the Kemp Loadbalancer (I'm trying to make things as simple as possible for my users).
dellock6
VeeaMVP
Posts: 6139
Liked: 1932 times
Joined: Jul 26, 2009 3:39 pm
Full Name: Luca Dell'Oca
Location: Varese, Italy
Contact:

Re: Reverse proxy SSL connections for vLab

Post by dellock6 »

But the cert is still handled by the original application like a web server, this is by far the most simple option.
If the issue is the cert not being validated because the SSL thumbprint is built with the original ip/hostname, you can just ignored the cert warning since it's a lab. If instead the cert is managed by an SSL reversed proxy, then you need to have also this machine in the lab to reproduce the production environment.
Luca Dell'Oca
Principal EMEA Cloud Architect @ Veeam Software

@dellock6
https://www.virtualtothecore.com/
vExpert 2011 -> 2022
Veeam VMCE #1
skrause
Veteran
Posts: 487
Liked: 106 times
Joined: Dec 08, 2014 2:58 pm
Full Name: Steve Krause
Contact:

Re: Reverse proxy SSL connections for vLab

Post by skrause »

Just an FYI, you don't have to have two vNICs on the Kemp (even though it has two in the initial image).

And I don't see why you couldn't do what you are asking by putting the certificates on the Kemp and then forwarding it to the virtual lab IP/port.
Steve Krause
Veeam Certified Architect
Post Reply

Who is online

Users browsing this forum: RRoberts and 117 guests