Forum Discussion
Loadbalancing based on UDP SSL certificate issuer
your requirements seems strange, and complex. I'd suggest contacting Professional Services for help with this, or take some time to describe your problem more clearly and somebody here may be able to help.
Yes, we contacted F5 PS and got response as "I have further reviewed the requirement and Wireshark traces with a senior colleague and we both concur that this is a non-starter due to the way the protocol behaves."
- Kannan_Thalaia1Oct 13, 2023Cirrus
the Radius Access Request packet is routed to the Authentication Server prior to the Client certificate being presented. This breaks any certificate-based routing that we require.
In the below diagram, step 5 (Access Request) happens before 5b (Client Cert request).
- PeteWhiteOct 13, 2023Employee
you could use an iRule which responds to the Access Request asking for the client cert, and once the client cert is presented it sends the request to the authentication server. Where is the BIG-IP sat in this flow?
- Kannan_Thalaia1Oct 13, 2023Cirrus
BIG-IP sit between Autheticator and Authentication server..
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com