Forum Discussion

WillUsable_1958's avatar
WillUsable_1958
Icon for Nimbostratus rankNimbostratus
Jun 06, 2017

F5 ADFS iApp to replace the ADFS proxy (WAP)

We are having issues using the AD FS iApp for the ADFS proxy with ADFS certificate multi-factor authentication enabled. The iApp created two VIPS, one on port 443 with access policy assigned, and one layer 4 on port 49443. ADFS certificate MFA works fine if we don't specify the ADFS claims rule based on location (inside the network). The iApp created the appropriate iRules to forward the x-headers, and the x-headers are present for the VIP on port 443.

 

F5 Version 12.1, AD FS 3.0

 

When we enable the ADFS claims rule for (insidethenetwork) on the ADFS server, certificate MFA does not work, the ADFS server is resetting the connection. It seems like the ADFS server thinks that the request on port 49443 is from inside the network, which does not require MFA, based on the claims rule below.

 

Anyone else run into this?