Forum Discussion
morrie_63651
Oct 11, 2007Nimbostratus
kerberos
I am planning to use my new F5 LTM to load balance a number of components that are protected by Microsoft Active Directory - Kerberos. I am being told that the F5 device must join the Kerberos domain. Can you tell me how this is accomplished?
Thanks,
--morrie
- DonDiego_23945NimbostratusHi,
- RyanLRoy_80296NimbostratusWhen you say "create an SPN for this dns name and with the userid being used to configure kerberos" which userid are you referring too? In our environment we have four servers which are load balanced. Kerberos based SSO is working on each individual server but is failing when going through the virtual ip. We have an AD user which corresponds to each physical machine. I believe the setspn command was then run for each of these users specifying the corresponding dns name of that server.
- Will_F_98397NimbostratusHello,
- edgar_26092NimbostratusWe are using F5 to load balance a wss 3.0 with kerberos authentication. Do you know necessary steps to expose the web site using f5 (witout moving kerberos settings) to our internal users that are outside the domain?. I see on another article that now F5 support this
- AVGuru_4933Nimbostratus
Posted By RyanLRoy on 12/10/2009 12:34 AM
- khaledmasmoudi_NimbostratusHi,
- theXfactor82_91NimbostratusWe have used the domaintool command on the load balancer to create the spn for the virtual IP and created an AD Computer object with the same name as the virtual IP. We are still getting 401 errors from IE 8.
Recent Discussions
Related Content
Â
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects