Forum Discussion
ActiveSync and Multi Domain SSO issue
While you can switch SSO profiles in an iRule, you cannot dynamically switch an assigned access profile. The general alternative for such a thing is what I outlined in option two. Understand that you have two different VIPs with two different access policies: one for standard non-multi-domain ActiveSync, and the other for everything else. An external VIP is used to broker the traffic to the appropriate internal access policy VIP based on the URI. The external VIP is simply LTM with an HTTP profile, a client SSL profile to terminate the HTTPS, and an iRule - no pool, no SNAT, and no APM. The virtual command produces no routing issues and no latency.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com