Forum Discussion
APM - Multiple sessions per single VS and APM profile/policy.
- Jul 11, 2019
It is not dedicated only to SWG, you can use with APM also to improve security of a webtop for example. When you attach a per-request policy to your VS, all your client requests are evaluated by this policy.
With a URL_branching box at the begining of the policy, you can decide what action to perform (like a new authentication) according to the URL requested by the client. The session variable to use is "perflow.category_lookup.result.url". Hope it's clear.
Hi,
In case you don't know, since v12 there is per-request policy functionality available that allow you to implement step-up authentication easily (using the same session).
You can find more information here: https://support.f5.com/csp/article/K42521259
My understanding that per-request is for Secure Web Gateway use only, which is why it talks about categorization.
Correct me if I'm wrong on this, but I'm looking purely at an APM reverse proxy stand point to allow resources, but treat each application as a separately governed session.
- JD1Jul 11, 2019Altostratus
Also, just to tack on the end of my last message - If Per-Request were to work outside of SWG, I believe that's protecting sub-areas of the same application. In this case I'm presenting different applications per host header, which need to be evaluated individually for the entire application.
Many thanks,
JD
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com