Forum Discussion
Layer 7 monitor and Cipher string.
Customer is trying to monitor Active Directory File Services and needs to use a layer 7 monitor. THe VIP uses prt 443 passthrough with a fastl4 profile. He has not had sucess with https://devcentral.f5.com/articles/big-ip-and-adfs-part-5-working-with-adfs-30-and-sn. He has also tried the https monitor. Using the HTTPS monitor I took a packet capture and saw the 3 way handshake, and a client hello, but no server hello. The customer is running 11.6.0. ADFS is working fine with BigIP. He is using the tcp monitor.
My question is related to the local/traffic/monitor cipher string. What would I place there given that the ADFS server supports the below?
From ADFS Server:
TLS_RSA_WITH_AES_128_CBC_SHA256 TLS_RSA_WITH_AES_128_CBC_SHA TLS_RSA_WITH_AES_256_CBC_SHA256 TLS_RSA_WITH_AES_256_CBC_SHA TLS_RSA_WITH_RC4_128_SHA TLS_RSA_WITH_3DES_EDE_CBC_SHA TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P384 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA_P256 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA_P384 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256_P256 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256_P256 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384_P384 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384_P384 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA_P256 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA_P384 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA_P256 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA_P384 TLS_DHE_DSS_WITH_AES_128_CBC_SHA256 TLS_DHE_DSS_WITH_AES_128_CBC_SHA TLS_DHE_DSS_WITH_AES_256_CBC_SHA256 TLS_DHE_DSS_WITH_AES_256_CBC_SHA TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA TLS_RSA_WITH_RC4_128_MD5 SSL_CK_RC4_128_WITH_MD5 SSL_CK_DES_192_EDE3_CBC_WITH_MD5 TLS_RSA_WITH_NULL_SHA256 TLS_RSA_WITH_NULL_SHA
3 Replies
- mikeshimkus_111Historic F5 Account
Hi Rick, assuming this is AD FS 3.0, you need to use the external EAV monitor. The built-in HTTP monitor will not work.
The downloadable .sh file from page 7 of this guide should be the correct one:
http://www.f5.com/pdf/deployment-guides/microsoft-adfs-dg.pdf
thanks
- Rick_Wiers_9833Historic F5 Account
Will check and let you know.
- Rick_Wiers_9833Historic F5 Account
Will check and let you know.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com