Forum Discussion
APM with external Logon page
In our case APM+LTM acts as reverse proxy and https offloading. So far it also does authentication to Active Directory. What are the security implications of using external logon page/web site instead of F5's built in logon page? Does it make easier to hack/DDOS the system? Or F5 is still on the the edge and making sure the security is the same?
Thanks !!!
1 Reply
as so often it depends:
if you run the external page on a raspberry pi with an unpatched apache connected via a 3G modem then you are quite susceptible for hacking / ddos.
if you place the website behind the LTM/APM that is currently in place the difference is quite small. as long as the server is maintained well.
if you run the external page on a well configured and regularly patched webserver, protected by a WAF and via an internet line protected by cloud based scrubbing service then it might be better.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com