Forum Discussion
ADFS Proxy, APM, ASM Craziness
- Nov 04, 2022
Ah got it as it seems like some guided configs F5 is using an internal iApp LX based on node js to make this magic and probably 404 is configured there.
We're working with support on this issue but there is no APM policy that is in use for ADFS. We are using the ADFS Trust portion that shows on a Virtual Server where you enter in Domain Admin creds to establish the trust and a certificate is autorenewed with the ADFS servers. That's where you see that anything which does not include a "/adfs" is presented with a 404. No ASM policy is in play.
Ah got it as it seems like some guided configs F5 is using an internal iApp LX based on node js to make this magic and probably 404 is configured there.
- JustCooLpOOLeNov 10, 2022Cirrocumulus
Definitely a nice feature but if you're trying to put an AWAF policy in front, the violations are never triggered. Looking into having a virtual server placed in front of the ADFS virtual server but that is challenging too
- WAQAR_IRSHADDec 12, 2022Nimbostratus
Hi
I am in planning stage to configure same scenario asm infront of adfs, kindly may you guide me the challenges you are encountring?
- JustCooLpOOLeDec 12, 2022Cirrocumulus
We ended up putting a virtual server for the AWAF policy and then sending it back to the ADFS virtual server.
Traffic -> AWAF VIP -> ADFS VIP
It would prefer if we could do everything on one VS but since APM is evaluated before AWAF, no violations will be triggered. One day F5 may re-evalute it but today is not that day...haha.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com