> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.co.in/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/docs/_mcp/server.

# SSL and TLS termination

> Terminate HTTPS at an IBEE Solutions L7 load balancer with a managed certificate, or pass TLS through untouched on L4 for end-to-end encryption.

How the load balancer handles encrypted traffic depends on the layer and protocol you pick at creation. There are two TLS modes:

| Mode            | Where you get it                   | Behavior                                                                                     |
| --------------- | ---------------------------------- | -------------------------------------------------------------------------------------------- |
| **Terminate**   | L7 with protocol `HTTPS`           | The load balancer decrypts traffic with a **managed certificate**, then forwards to backends |
| **Passthrough** | L4 with protocol `tls_passthrough` | Encrypted traffic is forwarded as-is — your backend holds the certificate and terminates TLS |

## Terminate at the edge (L7 HTTPS)

Create an **L7** load balancer with protocol **HTTPS**. The platform provisions and manages the certificate — there is nothing to upload or renew.

Traffic from the load balancer to your backends is plain HTTP by default. To re-encrypt the hop to a backend, tick **Encrypt traffic from the load balancer to this backend** on that backend row — the load balancer then connects to it over TLS.

Use termination when you want:

* Managed certificates with no renewal work
* L7 features that need to read the request — path/header rules, sticky sessions

## Pass TLS through (L4)

Create an **L4** load balancer with protocol **tls\_passthrough**. The load balancer forwards encrypted bytes without decrypting, so:

* Your backends present their own certificate and terminate TLS themselves
* End-to-end encryption is preserved — the load balancer never sees plaintext
* L7 features (path rules, header matches, sticky sessions) are not available, since the traffic can't be inspected

Choose the health check type accordingly — with passthrough, use a **TCP** check, or an **HTTPS** check if the backend exposes a health endpoint over TLS.

## Use your own domain

The detail page shows the load balancer's public endpoint **Host**. To serve traffic on your own domain, create a DNS record at your DNS provider that points your domain at that endpoint.

## Related pages

* [Create a load balancer](/docs/network-security/load-balancer/create-a-load-balancer)
* [Health checks](/docs/network-security/load-balancer/health-checks)