For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

NeilS_168972's avatar
NeilS_168972
Icon for Nimbostratus rankNimbostratus
Sep 04, 2014

Issue with Autodiscover via F5

Currently having issues with AutoDiscover (only last couple of days) for O365 clients. This was working fine since we setup the Irule and necessary Data Group list for *.outlook.com, *.onmicrosoft.com etc..

 

When we run the online check via MS Website the test passes fine but complains about Client Cert/SSL. When we run a TCPDUMP on the F5 we can see a RESET of the connection and on a Wireshark trace on the client we can see a RST/ACK from the F5 to the client almost immediately after AutoDiscover process starts.

 

Any help would be appreciated.

 

Thanks

 

NeilS

 

3 Replies

  • Bypassing the F5s resolves the issue but we need to get this working again via the F5s.
  • Why did you have to put an iRule in place to check for *.outlook.com and *.onmicrosoft.com? It would be nice if you shared your ideas and design here so that we can comment and discuss the approach. If you see BIG-IP send a RST, perhaps you can temporarily turn on loggong of RST cause as described here to see why it is happening?

     

    http://support.f5.com/kb/en-us/solutions/public/13000/200/sol13223.html

     

  • Thanks for the advice Michael - I will turn on the RST logging to see the cause of the issues when I return to the office tomorrow. Nothing has changed from the F5 configuration in the last 2 days when the issues began to occur so not sure if it is truly a configuration issue or some threshold has been hit (or the client has issues).

     

    I will update the thread with more information tomorrow.