Forum Discussion
cannot target different APM VIPs from irule attached to HTTP_REQUEST event, because HTTP::path changes to my.policy, etc.
That's an interesting and very valid scenario. Here are a few options:
-
Clientless-mode - if you don't have "disruptive" mechanisms in your access policy, like message boxes and logon forms, clientless-mode will bypass the /my.policy redirect, validate the access policy, send data to the server, and then add the APM session token to the FIRST server response. This is typically used with clients that don't support the redirects, but certainly an option here. You just need to add a "clientless-mode" header to the HTTP_REQUEST event of the APM VIPs:
when HTTP_REQUEST { HTTP::header insert "clientless-mode" 1 } -
When the APM VIP sends that /my.policy redirect, it'll also send the initialized session cookie. The trick then is to catch that response in an external LTM iRule and create a session table entry that maps the session cookie to the APM VIP. On subsequent requests, if "/my.policy", look up and forward based on the cookie. After policy evaluation is over, you should never see /my.policy again and can go back to URI-based balancing.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com