Forum Discussion
morrie_63651
Oct 11, 2007Nimbostratus
kerberos
I am planning to use my new F5 LTM to load balance a number of components that are protected by Microsoft Active Directory - Kerberos. I am being told that the F5 device must join the Kerberos domain...
Ravi_Rajan_7549
Nimbostratus
Hi,
Firstly map the virtual IP to a dns name in your internal DNS server. Then create an SPN for this dns name and with the userid being used to configure kerberos.
For ex. if you are using an id - xyz for configuring BO SSO, and the dns name is bovirtual.addomain.com
Then the SPN will be -
setspn -A HTTP/bovirtual.addomain.com xyz
Let me know how it goes.
Regads,
Ravi
pjcampbell_7243
Nov 08, 2017Cirrus
Logged to let you know this worked for me. Thanks!
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects