Forum Discussion

olivierb_69026's avatar
olivierb_69026
Icon for Nimbostratus rankNimbostratus
Oct 23, 2018

APM SSL VPN - Security Alert we want to get rid of

Hello,

 

Context: SSL VPN through APM

 

Everything is working fine so far but ... I am asking the question because we are facing two kinds of Security Alerts:

 

1 - After the VPN is established, we would like to launch a "gpupdate", what we configured in the according field. But once it is triggered, a pop up prompts to ask the end user to confirm:

 

 

It says : "The web site ... tries to execute a local application: .... Do you want to continue ?" (the URL is the one of the public facing SSL VPN) The thing is that happens on fully managed computers well hardened laptops of a public sector company, in an AD with SCCM, AV, PKI, etc. We already got rid of the browser pop up warning for the host checker and another one for the certificate checks but can not get rid of this one. First of all, it seems to be a F5-triggered pop up. Is it ? Does it need elevated privilege to run F5 Edge Client ?

 

2 - It happens that another Security Alert of the same kind (same "16-bits-like-old-school-grey") telling the network drive is already mapped and asking to map onto another letter OR disconnect existing drive OR abort. If any could come along for this one as well, I am all ears.

 

 

Quite important questions in a time of evaluating the F5 solution to replace the SSL VPN.

 

Bonus question as long as we are in SSL VPN and security: does someone know if the Windows SSL VPN client (based on "F5 Access" component) is already handling Machine Certificates in MY ? Because the logs are still showing an exit result of -2 with Windows Client but works fine with Edge. I read litterature about 11.4 and 12 .. but nothing for version 13.x.

 

Thank in advance for the inputs / experiences or paths.

 

/ Olivier

 

No RepliesBe the first to reply