Forum Discussion
F5 Deployment Options for Microsoft AD FS
Hi,
Load balancing the AD FS Proxy servers isn't required; the diagram is displaying that option. You can deploy AD FS Proxy behind LTM, or on its own. Both would forward traffic to an LTM fronting the AD FS servers.
If you just have AD FS servers, you can secure them with APM doing pre-auth and SSO; no AD FS Proxy required in that scenario.
You could do 4 by deploying the iApp twice on the same pair of LTMs, with the AD FS Proxy VS listening only on the DMZ VLAN(s) and the Proxy server pointing to the AD FS VS, which would be listening on the internal VLAN. The AD FS VS would need to be Fast L4 (no SSL decryption).
Does that help?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com