Forum Discussion
ADFS Proxy, APM, ASM Craziness
- Nov 04, 2022
Ah got it as it seems like some guided configs F5 is using an internal iApp LX based on node js to make this magic and probably 404 is configured there.
I've done some work on the ADFS Proxy but not with both that and ASM. What you are saying makes sense though - traffic is destined to APM ( rather than to a backend server, which is what ASM is more normally used for ) and APM translates them to the Microsoft ADFS proxy protocol. Have you looked at https://support.f5.com/csp/article/K13315545
Hi Pete,
So what'eve we found is that once we add the /adfs to the URL, we get a 404 response code with no event logs for ASM. We believe that using the ADFS Proxy setting on a virtual server, the BIG-IP will allow anything with /adfs in the URL to be processed by ASM but if a request doesn't start with /adfs in the URL, it immediately gives a 404 response code. No iRules were in play to provide that.
While we're happy that APM is providing some sort of security, we get no logs out of this to send to our SIEM. We looked at that article so we're looking into it. We're onto another problem with version 15 not supporting ADFS 5.0.
- Nikoolayy1Oct 08, 2022MVP
It could be a url filter or layer 7 access list in the APM session policy or if there is a per-request policy. You can also enable APM HSM logging to try to see the APM logs that block this:
https://support.f5.com/csp/article/K45423041
See at the end of this link about HSM with APM:
ASM can use the APM session id for user session matching:
As your APM is before the ASM you can also place the ASM before the APM to protect the login page or webtop if you use those. But in this case maybe the session feature will not work as the APM will be after the ASM but still the ASM may track by username by the login page:
https://support.f5.com/csp/article/K13315545
https://support.f5.com/csp/article/K54217479
- Nikoolayy1Oct 10, 2022MVP
I created a test adfs config and I take my words back as by default the ADFS config shouldn't provide any URL protections but if you modified it and if the ASM/Advanced WAF is the one doing this as it could block without returning custom page if someone has made it so.
ADFS config with APM authentication and F5 SMS OTP:
- JustCooLpOOLeNov 03, 2022Cirrocumulus
We're working with support on this issue but there is no APM policy that is in use for ADFS. We are using the ADFS Trust portion that shows on a Virtual Server where you enter in Domain Admin creds to establish the trust and a certificate is autorenewed with the ADFS servers. That's where you see that anything which does not include a "/adfs" is presented with a 404. No ASM policy is in play.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com