Server Name Indication
Server Name Indication (SNI) is an extension to the SSL and TLS protocols that indicates a server
name or website that a client is attempting to connect with at the start of the handshake process.
It allows a server to present multiple certificates on the same IP address and port number, thus
allowing multiple secure (HTTPS) websites to be server of the same IP address while allowing all
of those sites to have unique certificates all serviced on the same cluster/IP address.
SNI objects are added to certificates that are in the certificate store on Equalizer and are
configured on HTTPS clusters.After a client connects with a TCP port on the load balancer, it
searches it's certificate store for the website name that was exchanged as part of the HTTPS
packet header. If the website is NOT presented on a certificate, the cluster's default certificate
will be returned to the client. If the website IS presented on a certificated, that certificate will be
returned to the client. Using SNI, additional websites are associated with certificates allowing a
certificate to be returned to a client for multiple website requests, thus minimizing the need to
purchase costly wild card certificates.
The following illustration shows the connection and certificate process with Equalizer and an
HTTPS cluster:
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
All Rights Reserved.
363
Equalizer Administration Guide
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......