Manual Chapter : Policy-Based Dynamic Egress Routing

Applies To:

  • F5 SSL Orchestrator

    21.1.0

Policy-Based Dynamic Egress Routing

Following are the steps to configure policy-based dynamic egress routing:

  1. Create a Local Traffic Policy:

    1. Navigate to the BIG-IP LTM module and define a local traffic policy tailored to egress routing requirements.

    2. Configure conditions and actions within the policy based on traffic conditions.

    3. Ensure Client SSL is enabled within the policy to handle SSL/TLS traffic appropriately.

    Refer to the Introducing Local Traffic Policies documentation for detailed guidance.

  2. Create the SSL Orchestrator Topology:

    1. Navigate to SSL Orchestrator > Configuration > Create Topology.

    2. Choose the appropriate topology type (Outbound Gateway or Inbound Gateway).

    3. Configure the basic topology settings, such as SSL settings, service chaining, and topology-specific routing configurations.

    4. Deploy the topology once the configuration is complete.

    Refer to SSL Orchestrator topologies documentation for detailed guidance.

  3. Attach the Traffic Policy to the SSL Orchestrator Virtual Server:

    1. Navigate to Local Traffic > Virtual Servers.

    2. Locate the virtual server object associated with your deployed topology.

    3. Click the Resources tab and attach the created BIG-IP LTM policy to the virtual server by selecting it from the Available list of policies.

    4. Click Finished to save your changes and apply the attached policy.

Result

Policy-based dynamic egress routing in SSL Orchestrator is configured. Traffic will dynamically route to appropriate egress routes as defined in the BIG-IP LTM policy, providing efficient traffic handling without complex layering solutions…