For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

cams3g_149836's avatar
cams3g_149836
Icon for Nimbostratus rankNimbostratus
Jun 30, 2014

BIGIP/LTM 11.2.1, RSA, APM, & OWA for Exchange 2013

We are still working with some basic authentication issues by my exchange guy wants to know how to configure to only aks for authentication on one url and let the others pass through. I have very limited training or experience with F5 or the command line. ANy help will be appreciated.

 

This is how the agent running on the old exchange server works today.

 

When user goes to Http://email.rjrt.com or Https://email.rjrt.com , redirect user to Https://email.rjrt.com/owa

 

When user goes to Https://email.rjrt.com/owa or Https://email.rjrt.com/ecp , challenge user for RSA credentials

 

If user goes to any of these links, just pass them thru with NO RSA challenge https://email.rjrt.com/ECP https://email.rjrt.com/EWS/Exchange.asmx https://email.rjrt.com/Microsoft-Server-ActiveSync https://email.rjrt.com/OAB

 

1 Reply

  • you can use the following irule :

    when HTTP_REQUEST {
     switch -glob [HTTP::uri] {
      "/ECP*" -
      "/EWS/Exchange.asmx*" -
      "/Microsoft-Server-ActiveSync*" -
      "/OAB*" { ACCESS::disable } 
      default { ACCESS::enable }
     }
    }
    

    You add this irule and your access policy to your Virtual Server and it should disable authentication for specified URI.