Forum Discussion

Rahim_Damji_184's avatar
Rahim_Damji_184
Icon for Nimbostratus rankNimbostratus
Feb 24, 2015

f5 APM edge client for IPHONE 8.1.3

Hi Folks:

 

Need some help with repect to the APM.

 

We are doing cert auth here is the APM policy

 

We are getting denies all the time I have uploaded the CA cert.

 

When we use the safari browser we get allow.

 

When we use the client we receive the following error:

 

 

Can I get some with the validation of my config and the expected behavior

 

Thanks,

 

Rahim

 

9 Replies

  • to recap, using iOS 8.1.3, when you use safari browser on the iPhone it works, but with the edge client on the same iPhone it doesn't?

     

    why do you use the different cert inspection items? does it still work on safari when you change that to client cert inspection?

     

  • I made it a very simple APM policy

     

     

    And changed the SSL CLIENT policy to request cert and through the browser I got the following successful message

     

     

    When I test the exact same configuration with the edge client

     

     

    I changed to ODCA browser looks good

     

     

    with client same result

     

    What troubles me is that the receive info on the edge client is WIN which makes scratch my head.

     

    Thanks for response.

     

    Rahim

     

  • Have you selected "use certificate" and the certificate in edge client configuration on the iphone? Just to be sure all pieces are ok.

     

    gianrico

     

  • Yes client cert has been checked off

     

    Seth I will adjust the parameters accordingly and let you know

     

    Rd

     

  • Adjusted accordingly same result turned on the debug does looks like the OCDA agent is working on the edge client as I do not see any cert authentication in the debug logs.

     

    The browser is working fine.

     

    • Gianrico_D_Ang1's avatar
      Gianrico_D_Ang1
      Historic F5 Account
      Enable apm log level to "informational" and look at the session variables content in /var/log/apm