Forum Discussion
SamS_81032
Nimbostratus
Jun 24, 2010Authentication Issue - Maybe Kerberos
I think we are having problems with Kerberos authentication.
Here is the scenario:
1. An AD authenticated user accesses a website hosted in Tier 1.
2. Tier 1 makes a request to the VS address of Tier 2.
3. When the node in Tier 2 receive the request the request is from an anonymous user.
4. Tier 2 needs to see the request from the AD authenticated user who accessed the web site on Tier 1 otherwise the request fails.
5. The authentication on Tier 2 works fine if Tier 1 goes directly to one of the nodes in Tier 2 (bypassing the F5).
The VS is set up using one-arm out-of-path with SNAT automapping so the Tier 2 servers will see the request coming from the IP of the F5.
Is there anyway to get the F5 to forward the request with the authentication details to Tier 2?
Thanks
Sam
- Chris_Miller
Altostratus
Are you running into SPN issues? - SamS_81032
Nimbostratus
It turned out to be SPN related. The problem has been fixed now.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects