Forum Discussion

Soujanaya_Sunku's avatar
Soujanaya_Sunku
Icon for Nimbostratus rankNimbostratus
Sep 18, 2013

Is there any documentation to do Mutual Auth?

Need that to do Mutual Auth with External Resouce

 

4 Replies

  • Could be ..i dont know what special authentication means...we want the connection be secured by verifying cert.

     

  • Ah, so client certificate authentication? If so, there's a few ways to tackle this:

     

    Starting with the most robust option, Access Policy Manager (APM) module has client cert inspection and revocation checking built right in. Guidance for this is in the APM guides on the support site.

     

    You can also technically do some of this with LTM directly. Guidance on this can be found in the authentication and SSL profile sections of the LTM guides, also on the support site.

     

  • You want to make sure a connecting user is authenticated and authorized to access certain resources on the BigIP (i.e VIPS). Kevin suggested "APM", which you will need a module license if you haven't already got that. Or, the LTM module suggested has in SSL authentication features. First you can do all your SSL client authentication within BigIP by ensuring that client certificates presented by the client browser at the beginning of the session is authorized by pre-loaded "Trusted CA" on the BigIP or Advertised CAs from the BigIP. This is simple and straight forward. The extended authentication can be offloaded to an external server (radius, tacas or ldap). In this case, client authentications are checked on the BigIP against what was pre-configured on external servers. The checks carried out (either user key, certificate map, certificates etc) must match in some form what was held in the ldap database. https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm_configuration_guide_10_1/ltm_auth_profiles.html1197346