Forum Discussion
opers13_3280
Nimbostratus
Sep 08, 2009F5 and RSA Token.
we are in the process of deploying two factor authentication...do I need any "special" config on the F5 side for it to pass authentication at all?
thanks
- The_Bhattman
Nimbostratus
I think you need a Authentication module license for this. You need to check with your F5 account manager who can tell you if you already have a license for this. - hoolio
Cirrostratus
What are you actually trying to do? You could potentially use RSA to authenticate admin traffic. This does not require an Advanced Client Authentication module. You could use RSA to authenticate client traffic. As cmbhatt suggestions, this would require the ACA add-on license. Or you could be just trying to load balance or route RADIUS communication through LTM. - opers13_3280
Nimbostratus
Ok...never mind the original question. Here's what our server guys are trying to accomplish: - hoolio
Cirrostratus
If you want to have LTM perform client authentication on a VIP you would need the ACA license. You can check to see if the ACA is listed as active or optional in your /config/bigip.license or in the GUI under System | License. If you see ADD CLIENT AUTHENTICATION under the Optional section you don't have it. You can contact your F5 account manager to get a quote for adding it. You need a license per LTM unit. - opers13_3280
Nimbostratus
thanks Aaron...i actually came across another thread that you replied with some useful links and realized I don't have the ACA module. - hoolio
Cirrostratus
If you're able to separate the clients by VLAN, you could configure the same type of virtual server on the different VLANs and keep things isolated that way. That would be the simplest option. If that's not possible, then you could potentially add two separate auth profiles to the same VS. Redstar mentioned in this this post that it worked for him: - opers13_3280
Nimbostratus
awesome thanks! - hoolio
Cirrostratus
If you get something configured and working, could you post an anonymised copy of the VIP, profile and iRule configuration?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects