Hi John, i'm still a newbie with BIG-IP, so forgive me if my question is stupid :). When would we use this STS instead of a irule with a HTTP::redirect command for redirecting a http request to a https url? Thank you in advance, Zach
@JasonRahm8 жыл бұрын
Strict Transport Security is a flag set on the server-side of the connection to instruct the client-side (ie, the browser) to always send a request via SSL to the server-side. If you are redirecting (which you need to do for the first request) requests then some client connects are being sent outside of SSL, which is not a desired behavior. Note that ultimately, settings like STS are client protection, not server protection. Consider this option as looking out for your customers.