Forum Discussion
ADFS config on F5
Am in the process of deplying ADFS , want to loadbalace ADFS servers and webproxy on the Loadbalancer . Can anyone help with me with the Configs related ADFS servers
26 Replies
- Abi80_167352
Nimbostratus
I am able to loadbalance Internal servers ,,however am having issues with loadbalacing with external webproxy which is on Public Ip If i have the IP of the servers and VIP configrued in 84.207.xx.xxx and if i am using automap on the VIP should i have SELF IP configrued in the same range to make it work . Please help Hello,
You don't have to be connected to the network where you need loadbalancing.
You should be able to configure a pool of servers on another network.
You may encounter a routing issue. Although, your VS has snat automap configured, your web proxy may not have a route back to the load balancer selfip, thus the default route may be used and packets goes in the wrong direction.
I recommend you to make sure that you have no routing issue on your network.
- Does the issue happen when you try and access the VIP through the web proxy? or does it happen when you go direct to the VIP when you have the web proxy disabled?
- Abi80_167352
Nimbostratus
both the servers are configrued with global ips 84...** and VIP is also in the same subnet 84...**
I tried chaging the default gateway to F5 but it did not work , If i get an Ip in the same subnet 84.xxx can i use in a pool and use SNAT
You can use snat automap on your VS if both F5 and pools are on the same subnet.
- Abi80_167352
Nimbostratus
will it create any issues
Is it poosible to add a global ip in automap config
You can use a snat pool with an IP address within that is located in this subnet
- Abi80_167352
Nimbostratus
thanks i used automap it works now howver now the websever is not showing any websites i can see connection requests going to and from the server
There is probably an authentication issue that can occurs if you are using kerberos or ntlm.
or this may be due to SSL (Supported ciphers, etc.)
or a persistence issue (did you configured a cookie persistence ?)
Do you have errors logs in your adfs servers. Do you see TCP handshake, SSL handshake and HTTP request and response ?
you can try accessing your webservers using
on CLI. You should see HTTP RESPONSE HEADERS if everything works as expectedcurl -k https://webserver_ip_addr -I- Abi80_167352
Nimbostratus
Hi Yann
this is response i get from teh websevers
curl -k https://84.xx.xx.xx -I HTTP/1.1 404 Not Found Content-Length: 315 Content-Type: text/html; charset=us-ascii Server: Microsoft-HTTPAPI/2.0 Date: Tue, 26 Aug 2014 07:46:02 GMT Connection: close
- Hello, it means that you get an answer from the web server. However, you get a 404 Not Found meaning that your webserver didn't find the webpage. Can you do the test again with the full url of your webapp ?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com