EasyManuals Logo

Cisco 11503 - CSS Content Services Switch Configuration Guide

Cisco 11503 - CSS Content Services Switch
250 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #129 background imageLoading...
Page #129 background image
4-47
Cisco Content Services Switch SSL Configuration Guide
OL-5655-01
Chapter 4 Configuring SSL Termination
Activating and Suspending an SSL Proxy List
To set the amount of data in bytes that a given connection can buffer from the
server to the client, use the tx number2 keyword and variable. By default, the
buffer size is 65536. The buffer size can range from 16400 to 262144. For
example, to set the value to 131072, enter:
(config-ssl-proxy-list[ssl_list1])# ssl-server 20 tcp buffer-share
tx 131072
To reset the reset the buffer size to the default of 65536, enter:
(config-ssl-proxy-list[ssl_list1])# no ssl-server 20 tcp
buffer-share tx
Activating and Suspending an SSL Proxy List
Before you can activate an SSL proxy list, ensure that you have created at least
one virtual or back-end SSL server in the list (see the “Configuring Virtual SSL
Servers for an SSL Proxy List” section or the “Specifying the Nagle Algorithm
for SSL TCP Connections” section earlier in this chapter).
The CSS checks the SSL proxy list to verify that all of the necessary components
are configured, including verification of the certificate and key pair against each
other. If the verification fails, the certificate name is not accepted and the CSS
logs the error message
Certificate and key pair do not match and does not
activate the SSL proxy list. You must either remove the configured key pair or
configure an appropriate certificate.
Use the active command to activate the new or modified SSL proxy list. For
example, enter:
(config-ssl-proxy-list[ssl_list1])# active
After you activate an SSL proxy list, you can add it to a service. See the
“Configuring a Service for SSL Termination” section later in this chapter.
Note No modifications to an SSL proxy list are permitted on an active list. Suspend the
list prior to making changes, and then reactivate the SSL proxy list once the
changes are complete. Once you have modified the SSL proxy list, suspend the
SSL service, reactivate the SSL proxy list, and then reactivate the SSL service.
To view the virtual or back-end SSL servers in a list, use the show ssl-proxy-list
(see Chapter 7, Displaying SSL Configuration Information and Statistics).

Table of Contents

Other manuals for Cisco 11503 - CSS Content Services Switch

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 11503 - CSS Content Services Switch and is the answer not in the manual?

Cisco 11503 - CSS Content Services Switch Specifications

General IconGeneral
BrandCisco
Model11503 - CSS Content Services Switch
CategorySwitch
LanguageEnglish

Related product manuals