Forum Discussion
Cert-Based Authentication to the Configuration Utility While Connected to an APM VPN
- Apr 29, 2020
unfortunately that is not possible, with SSL config like that (client and server side ssl profile) the client cert wont get further then the client side profile.
you could try without the SSL profiles and see if it then works, but probably not.
another way would be to put the client cert on the server side profile, but that kinda defeats your client certificate authentication.
proxy SSL might be an option, but you need to disable quite some ciphers
https://support.f5.com/csp/article/K13385
using a hop server is another possibility.
unfortunately that is not possible, with SSL config like that (client and server side ssl profile) the client cert wont get further then the client side profile.
you could try without the SSL profiles and see if it then works, but probably not.
another way would be to put the client cert on the server side profile, but that kinda defeats your client certificate authentication.
proxy SSL might be an option, but you need to disable quite some ciphers
https://support.f5.com/csp/article/K13385
using a hop server is another possibility.
- Jim_ChapuranApr 30, 2020Altostratus
Thanks for the response. That is unfortunate. I guess my only follow-up is, is there any way to bypass that "security feature" Kevin Stewart alluded to in his earlier answer and use the primary IP instead of a VS?
Our goal is to prevent "public" access to the console and only allow it from behind the VPN, using AD account certs. We've been able to do this with every other server and site that we run, so this is the last use of passwords for our privileged accounts - I'd really like to nix the password usage once and for all.
- boneyardApr 30, 2020MVP
wasnt even aware it was security feature, always assumed more a traffic routing issue.
it would be worth a support ticket for sure.
next to that you might be able to some NAT construction on another device, getting the traffic to leave the BIG-IP and return from a different source IP, i would imagine that is enough to get acces.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com