Forum Discussion
NTLM Authentication - Windows Integrated 401 Challenge
To validate if it comes from the backend, check the server logging. It should give an unauthenticated user.
For KDC configuration, look at the manual. hint: 1. the F5 account needs delegation rights for the SPN of the backend server. (see manual how to do that) 2. so for your environment, you first have to setup SPN for your sharepoint. 3. within your kerberos SSO configuration, use the SPN patternfield and fill in the SPN; something like HTTP/service.contoso.com@CONTOSO.LOCAL
If you do not use the SPN pattern then the F5 will use reverse DNS lookup of the poolmember IP address to find the SPN (which probably has incorrect PTR settings).
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com