<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How to configure RRAS based SSTP VPN server behind F5 BIGIP SSL load balancer</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/05/26/configuring-rras-based-sstp-vpn-server-behind-f5-bigip-ssl-load-balancer.aspx</link><description>Hello All, 
 In this blog, I will discuss how to load balance SSTP based VPN servers using a F5 BIGIP SSL load balancer. 
 Lets look at the deployment scenario first: You are having a pool of RRAS based VPN servers hosted behind F5 BIGIP load balancer</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Configuring RRAS based SSTP VPN server behind F5 BIGIP SSL load balancer</title><link>http://blogs.technet.com/b/rrasblog/archive/2009/05/26/configuring-rras-based-sstp-vpn-server-behind-f5-bigip-ssl-load-balancer.aspx#3245816</link><pubDate>Tue, 26 May 2009 19:44:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3245816</guid><dc:creator>adimcev</dc:creator><description>&lt;p&gt;Samir wrote:&lt;/p&gt;
&lt;p&gt;&amp;quot;SSL Certificates: Import the SSL certificate that will be used during HTTPS negotiation. Please note: the subject name (CN) of the certificate should be same as the VPN destination name as configured inside VPN client.&amp;quot;&lt;/p&gt;
&lt;p&gt;This may be partially correct for Windows SSTP clients. -;)&lt;/p&gt;
&lt;p&gt;If the certificate contains a SAN DNS Name entry, then this name will be verified by the client(at least according to my tests), if failed, the error on the SSTP client is inaccurate(will say that the CN was wrong, which was &amp;nbsp;not the case).&lt;/p&gt;
&lt;p&gt;In practice, the CN may be the same with the SAN DNS Name entry, so one could not tell the difference and likely will not get any errors.&lt;/p&gt;
&lt;p&gt;If the SAN on the server's certificate contains multiple DNS Name entries, the SSTP client appears to be capable to &amp;quot;consume&amp;quot; these entries(at least I saw this behavior with Vista SP2 RC and Win 7 RC SSTP clients, which is pretty cool).&lt;/p&gt;
&lt;p&gt;The client's SSL Hello message contains the Extension: server_name with the name of the server configured on the VPN connection.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Adrian&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3245816" width="1" height="1"&gt;</description></item></channel></rss>