For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Abi80_167352's avatar
Abi80_167352
Icon for Nimbostratus rankNimbostratus
Aug 20, 2014

ADFS config on F5

Am in the process of deplying ADFS , want to loadbalace ADFS servers and webproxy on the Loadbalancer . Can anyone help with me with the Configs related ADFS servers

 

26 Replies

  • again

     

    HTTP/1.1 400 Bad Request Content-Length: 0 Server: Microsoft-HTTPAPI/2.0 Date: Tue, 26 Aug 2014 08:11:32 GMT

     

  • These webserevrs are configured with Public Ips should i be using SSL certificate on the F5 ora normal L4 profile will work

     

    • Yann_Desmarest's avatar
      Yann_Desmarest
      Icon for Cirrus rankCirrus
      You can check directly on your webserver. You can also test your Virtual Server from cli : curl -k https://VS_ip_addr -I
  • tested for curl -k https://VS_ip_addr -I did not get any output

     

    it was blank

     

    • Yann_Desmarest's avatar
      Yann_Desmarest
      Icon for Cirrus rankCirrus
      Try to switch to Standard VS in your configuration and add profile for SSL client and server
  • got the message ssl session timeout

     

    curl -k https://VIP Ip -I

    curl: (28) SSL connection timeout

     

  • ltm virtual Adfs_Webproxy { destination 84.xx.xx.xx:https ip-protocol tcp mask 255.255.255.255 persist { cookie { default yes } } pool Adfs_Webproxy profiles { ADFS_Server_SSL { context serverside } http { } ntlm { } oneconnect { } tcp { } } source 0.0.0.0/0 source-address-translation { type automap }

     

    • Yann_Desmarest's avatar
      Yann_Desmarest
      Icon for Cirrus rankCirrus
      a clientside ssl profile is missing. Moreover, you should enable "translate-address" and "translate-port"
  • Thanks Yann

     

    Looks like we got sumewhere now it gives this error

     

    Service Unavailable

     

    HTTP Error 503. The service is unavailable.

     

  • Hi Yann

     

    Trying set health monitor for webproxy both are on https profiles

     

    can you suggest any https monitor which can be used for adfs webproxy

     

  • You can normally use :

     

    https_443 or https_head_f5

     

    you can also monitor a custom url by creating a new monitor based on https_443