Forum Discussion
Posterus_85681
Nimbostratus
Sep 29, 2015clientless-mode, session-cookie and policy re-evaluation
Hi Everyone,
I am trying to use the inbuilt OTP functions within APM, so that they can be consumed by other systems that want to use OTP.
I have managed to use clientless-mode and have a sy...
Posterus_85681
Nimbostratus
Oct 06, 2015It does work. Because the APM policy can not be re-evaluated thats why we connect back with MRH cookie and then compare the OTP code to verify from the ext system via header variable and compare this to the session.otp.assigned.val value that was generated (this is done in the http request section)
Stanislas_Piro2
Cumulonimbus
Oct 07, 2015When I look in your configuration, everything is allowed... there is no reject if the OTP code is wrong or the client does not provide a OTP code.
If the first request contains generate, the APM allow the connection...
if in the following requests, there is no generate or verify, the irule allow connection.
the decision to allow or not the connection is not made by APM but by the client which receive the OTP status.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects