> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.ibee.co.in/docs/network-security/load-balancer/ssl-and-tls-termination/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/_mcp/server. # SSL and TLS termination > Terminate HTTPS at an IBEE Solutions L7 load balancer with a managed certificate, or pass TLS through untouched on L4 for end-to-end encryption. How the load balancer handles encrypted traffic depends on the layer and protocol you pick at creation. There are two TLS modes: | Mode | Where you get it | Behavior | | --------------- | ---------------------------------- | -------------------------------------------------------------------------------------------- | | **Terminate** | L7 with protocol `HTTPS` | The load balancer decrypts traffic with a **managed certificate**, then forwards to backends | | **Passthrough** | L4 with protocol `tls_passthrough` | Encrypted traffic is forwarded as-is — your backend holds the certificate and terminates TLS | ## Terminate at the edge (L7 HTTPS) Create an **L7** load balancer with protocol **HTTPS**. The platform provisions and manages the certificate — there is nothing to upload or renew. Traffic from the load balancer to your backends is plain HTTP by default. To re-encrypt the hop to a backend, tick **Encrypt traffic from the load balancer to this backend** on that backend row — the load balancer then connects to it over TLS. Use termination when you want: * Managed certificates with no renewal work * L7 features that need to read the request — path/header rules, sticky sessions ## Pass TLS through (L4) Create an **L4** load balancer with protocol **tls\_passthrough**. The load balancer forwards encrypted bytes without decrypting, so: * Your backends present their own certificate and terminate TLS themselves * End-to-end encryption is preserved — the load balancer never sees plaintext * L7 features (path rules, header matches, sticky sessions) are not available, since the traffic can't be inspected Choose the health check type accordingly — with passthrough, use a **TCP** check, or an **HTTPS** check if the backend exposes a health endpoint over TLS. ## Use your own domain The detail page shows the load balancer's public endpoint **Host**. To serve traffic on your own domain, create a DNS record at your DNS provider that points your domain at that endpoint. ## Related pages * [Create a load balancer](/docs/network-security/load-balancer/create-a-load-balancer) * [Health checks](/docs/network-security/load-balancer/health-checks) > Terminate HTTPS at an IBEE Solutions L7 load balancer with a managed certificate, or pass TLS through untouched on L4 for end-to-end encryption.