Forum Discussion
How to make access profile allow non auth'ed people in
Hi,
I think you are on the right track. A policy with "Start ---> Allow" will work, everyone will pass without the need to further authenticate.
Pay attention, in your example above you are mixing http and https URLs. If your VS is listening on http and you Access Policy has a setting for "Cookie Options: Secure" enabled it won't work with http, only with https.
A cookie with the Secure attribute set is sent to the server only over https.
If you apply an Access Policy with "Cookie Options: Secure" enabled to a http virtual then APM will display a blocked page saying "Access was denied by the access policy."
The idea of have a Pre-Request Policy for /secret is also right.
KR
Daniel
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
