Forum Discussion
ADFS config on F5
Am in the process of deplying ADFS , want to loadbalace ADFS servers and webproxy on the Loadbalancer . Can anyone help with me with the Configs related ADFS servers
26 Replies
- Abi80_167352
Nimbostratus
again
HTTP/1.1 400 Bad Request Content-Length: 0 Server: Microsoft-HTTPAPI/2.0 Date: Tue, 26 Aug 2014 08:11:32 GMT
- Can you confirm the authentication type requested by the webserver ?
- Abi80_167352
Nimbostratus
These webserevrs are configured with Public Ips should i be using SSL certificate on the F5 ora normal L4 profile will work
- Abi80_167352
Nimbostratus
Hi Yann
how can i check on the authentication type ?
- You can check directly on your webserver. You can also test your Virtual Server from cli : curl -k https://VS_ip_addr -I
- Abi80_167352
Nimbostratus
tested for curl -k https://VS_ip_addr -I did not get any output
it was blank
- Try to switch to Standard VS in your configuration and add profile for SSL client and server
- Abi80_167352
Nimbostratus
got the message ssl session timeout
curl -k https://VIP Ip -Icurl: (28) SSL connection timeout
- Can you post the configuration of your VS and pool ?
- Abi80_167352
Nimbostratus
ltm virtual Adfs_Webproxy { destination 84.xx.xx.xx:https ip-protocol tcp mask 255.255.255.255 persist { cookie { default yes } } pool Adfs_Webproxy profiles { ADFS_Server_SSL { context serverside } http { } ntlm { } oneconnect { } tcp { } } source 0.0.0.0/0 source-address-translation { type automap }
- a clientside ssl profile is missing. Moreover, you should enable "translate-address" and "translate-port"
- Abi80_167352
Nimbostratus
Thanks Yann
Looks like we got sumewhere now it gives this error
Service Unavailable
HTTP Error 503. The service is unavailable.
- Abi80_167352
Nimbostratus
Hi Yann
Trying set health monitor for webproxy both are on https profiles
can you suggest any https monitor which can be used for adfs webproxy
You can normally use :
https_443 or https_head_f5
you can also monitor a custom url by creating a new monitor based on https_443
- Abi80_167352
Nimbostratus
can i know what to configure as get and recieve string
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com