Forum Discussion
ADFS proxy not working
We have F5 hardware load balancer which do the load balancing job for ADFS proxy server requests with certificates configured in F5, We have replaced SHA 1 certiifcates with SHA2 (sha256)certificates both on servers & as well in F5 post that external users are not able to login to ADFS relying party applicatons whereas internal one's working fine
Internal request---F5(No Certificate)---ADFS 3.0 (Hosted 2012 R2) servers External request--F5(Certificate)---ADFS proxy servers (Hosted on 2012 R2 servers)---ADFS servers
In ADFS proxy servers, we are finding many CIPHER errors which came after certificate renewal. Post roll back to old certificate errors are gone
Currently on F5 it is configured with default Cipher settings, Can someone have any idea whether it require any changes related to CIpher suite
If i change the Cipher suite will it impact other VIP's
Log Name: System
Source : Schannel
Event ID: 36888
Time : 6/15/2015 10.01 AM
Level : Error
User : System
Computer : abc
Description: A fatal alert was generated and sent to remote endpoint. This may result in termination of connection. The TLS protocol defined fatal error code is 40. The windows Schannel error state is 1205
Log Name: System
Source : Schannel
Event ID: 36874
Time : 6/15/2015 10.01 AM
Level : Error
User : System
Computer : abc
Description: An TLS 1.2 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed
7 Replies
i have some experience with windows server not liking TLS1.2 yet, you could try with a cipher like !TLSv1_2:DEFAULT
- Ryannnnnnnnn
Altocumulus
we are in the process of configuring servers for ADFS and i came across this issue last week. our ADFS proxies sit behind a couple of units running 11.6 (i had to disable TLS1.2 in the server SSL profile in order to get things working), while our internal ADFS servers sit behind a couple of units running 10.2.3 (no issues).
10.2.3 supports a limited number of ciphers with TLS1.2, it might be those don't cause issues.
- Lars_Forsgren
Nimbostratus
We have 11.4.1 on both external (proxy connection) and internal F5. The problem is only on the external one. If we connect an ADFS proxy directly to internet the problem goes away. Can it have something to to with the SNI part? That is only used in the proxy configuration. The communication between proxy and internal ADFS (through F5) is not SNI configured in my setup.
- are you the same person as the original poster? if not it might be wise to start a new question with your details.
- LarsF_210108
Nimbostratus
We have 11.4.1 on both external (proxy connection) and internal F5. The problem is only on the external one. If we connect an ADFS proxy directly to internet the problem goes away. Can it have something to to with the SNI part? That is only used in the proxy configuration. The communication between proxy and internal ADFS (through F5) is not SNI configured in my setup.
- are you the same person as the original poster? if not it might be wise to start a new question with your details.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
