Forum Discussion
Javier_124486
Nimbostratus
Dec 20, 2017NTLM fallback path is not been selected
Hello everyone,
I've been trying to configure an APM policy to authenticate the users transparently via NTLM as long as the user's computer is Joined to the domain else they should be shown the ...
Stanislas_Piro2
Cumulonimbus
Dec 25, 2017Hi,
the issue is client still try to authenticate because of 401 response.
NTLM auth is done before Access policy is evaluated, so it never follow fallback branch.
NTLM auth result is not a NTLM auth action but a validation of NTLM auth performed at LTM level.
try with following code to disable NTLM auth if first attempt fails.
when ECA_REQUEST_DENIED {
log local0. "User [ECA::username]@[ECA::domainname], Client Machine [ECA::client_machine_name], Auth Status [ECA::status]"
ECA::disable
}
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects