Forum Discussion

KenJ_50171's avatar
KenJ_50171
Icon for Nimbostratus rankNimbostratus
Mar 06, 2010

F5 in front of a Shibboleth-authorized application

This is real shot-in-the-dark time.

 

 

I'm trying to put the F5 LTM in front of a Shibboleth-authorized application. There seems to be some sort of gotcha here which I have not figured out -- it works fine if there is only one server but the user web browser gets lost when there are two back-end servers.

 

 

I can find plenty of references on the Google to putting a Shibboleth server behind the F5, but nothing about putting a service which uses Shibboleth authentication behind an F5, or other load balancer.

 

 

Anyone done this, any thoughts about what has to be done differently? Is something mangling my persistence cookies?

 

 

Puzzledly yours...
  • hoolio's avatar
    hoolio
    Icon for Cirrostratus rankCirrostratus
    Hi Ken,

     

     

    Do you have persistence configured on the VIP? This would ensure the same client is sent to the same pool member over the duration of their session. You could try cookie insert or less ideally source address persistence to start with.

     

     

    Aaron