Re: SSL Certificates on NLB Cluster

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Correct. Affinity needs to be either Single or Class C for SSL to work with
NLB. Use Class C to bundle IPs from class C subnets to the same NLB host
computer.

Cheers,

Rodney R. Fournier

MVP - Windows Server - Clustering
http://www.nw-america.com - Clustering Website
http://www.msmvps.com/clustering - Blog
http://www.clusterhelp.com - Cluster Training
ClusterHelp.com is a Microsoft Certified Gold Partner


"Jay" <Jay@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DF592D2F-B478-4E9E-8940-E5AAA67C67E2@xxxxxxxxxxxxxxxx
Scenario: 2 Win 2003 Servers running in NLB Cluster mode hosting an
Asp.NET
application on IIS 6.0. I wish to install SSL certificate to secure the
site.
I have two options:
i) Generate Cert Request from each server and then proceed to install the
respective certificates.
ii) Generate Cert Request from one server and then install the certificate
on it and then export the certificate on to the other server.

If the cluster is configured to None affinity, then the user will go to
anyone of the servers forcing client key exchange (ssl) each time and
hence
making the process more expensive. [Ethereal Packet Capture shows this.]
The
only way I see is to set the Cluster to Single Affinity to enforce the
client
to go to the same server to maintain the ssl session.

My question is "Does installing SSL on NLB cluster force us to go for
Single
Affinity to avoid 'SSL Handshakes, Client Key exchange' on each visit?"


.



Relevant Pages

  • Re: FE/BE migration help !
    ... I can seem to figure out how to install SSL on the cluster.. ... redirect for the default site on the existing server and FBA enabled.. ... mailbox that lives on the new cluster... ...
    (microsoft.public.exchange.admin)
  • Re: FE/BE migration help !
    ... I can seem to figure out how to install SSL on the cluster.. ... redirect for the default site on the existing server and FBA enabled.. ... mailbox that lives on the new cluster... ...
    (microsoft.public.exchange.admin)
  • Re: FE/BE migration help !
    ... redirect for the default site on the existing server and FBA enabled.. ... I have no problem exporting and importing the SSL cert.. ... OWA now works fine on the cluster albeit without ...
    (microsoft.public.exchange.admin)
  • RE: SSL for a clustered web site
    ... Certificate Server: ... W2K/Certificate Server 2.0 server set up for testing purposes, ... SSL generally: ... cluster - you should check with them on licensing requirements. ...
    (microsoft.public.inetserver.iis.security)
  • Re: TSe & NLB ... so close??!!
    ... If ok, then activate the affinity (i would do it anyway, so local profile are not too much created) ... Using Terminal Server with Windows Load Balancing Service ... Terminal Services Client Cannot Connect to NLB Cluster TCP/IP Address ...
    (microsoft.public.windows.server.clustering)