Forum Discussion
How to configure 2 forest in Bigip APM
Well, it looks like w.test@DOMAIN2 is the user performing client side NTLM authentication to APM. If you're expecting some DOMAIN1 user, based on the Outlook profile, to be the one logging in, then you might have something misconfigured in Outlook. In any case, you're getting all the way to the Kerberos SSO functions, so you can be reasonably certain that client side authentication is working. Troubleshooting Kerberos SSO is a bit more involved, so you'll definitely want to enable APM SSO debug logging while you're working on this. That should at least give you more detailed logging. Are you hard-coding a domain name in the session.logon.last.domain session variable? If not, just for testing of DOMAIN2 users, try setting it manually in a variable assignment:
session.logon.last.domain = expo { "DOMAIN2" }
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com