Forum Discussion
F5 with websense with Kerberos authentication
Hi,
I reccently moved to F5 LTM module and I want to configure my F5 to work with my WEBSENSE PROXY's servers with kerberos authentication. I setted up all the proxy servers to work fine with kerberos authentication and I get a ticket successfully when i sufring through each one of them. The problem is that when I surfing through the FQDN of the VIP that is configured on the F5 iApps VS I dont get a ticket and thhere is fallback to NTLM. It seems that the F5 doesn't forward the kerberos request
What is the special configuration I need to do on the F5 wo the kerberos will work successfully
Please Help !!
- AneshCirrostratus
is your virtual server FQDN same as the SPN of the Websense?If not, it should be same so you can pass a Kerberos ticket through the VIP
Remember that the BIG-IP is a full proxy. You'll need to configure Kerberos Auth in the clientside context and Kerberos SSO in the serverside context. For more info see:
clientside
serverside
- Mohamed_Ismail1Nimbostratus
To forward Kerberos tickets though LB need special configuration at Domain controlled side(DNS),
Refer below article, it may hellp :
https://support.forcepoint.com/KBArticle?id=Kerberos-and-Integrated-Windows-Authentication-in-a-load-balanced-environment Sorry for the late reply, this may be helpful for others.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com