Forum Discussion
rluyster
Nimbostratus
Apr 15, 2008Prompting for passwords
I have set up a virtual server with only one server behind it. It is a simple HTTP connection, however when I try to access the application, I am prompted to enter my userid and password. When accessing the application directly on the server this is not the case. To make things even worse, I have now discovered that some users are not prompted when accessing via the F5 while others still are. No one is prompted when not passing thru the F5.
- hoolio
Cirrostratus
Are you performing source address translation on the BIG-IP? If so, the client IP address that the web server sees would change. Does the web server request credentials form the client through the BIG-IP because the IP address isn't what it's expecting? - rluyster
Nimbostratus
Aaron - hoolio
Cirrostratus
It's very odd that only some users are prompted for a password through the BIG-IP. Is it possible that some users already entered a password and their browser is caching it? Do you see in the server logs that the users which don't get prompted have an authorization header with a user/pass (or NTLM token) set? - rluyster
Nimbostratus
We are not able to change the server, here is the interesting part of all of this, I have dumped the interfaces, when it works, the client gets back a ""401 not authorized" and then sends a NTLMSSP_Negotiate, when it fails the client sees the "401 not authorized" but it does not send the NTLMSSP_Negotiate, now for the real interesting part. from the same client, with no changes, if I try to hit the server by the IP of the virtual server in the BIG-IP it fails, however if I set up a DNS entry for the IP of the virtual server and hit the server by name, it works every time and so far from every machine. - hoolio
Cirrostratus
When clients make a request directly to the server by IP address, do they get the same results as when they access the VIP by IP address? - rluyster
Nimbostratus
No, access directly to the server works wether the client uses the IP address or the name. The frustrating part has been that sometimes it will also work thru the BIG-IP, I just can't place my finger on why or when, from the same machine it may not work in the morning but does in the afternoon. I too am not that familiar with NTLM but this link looks like a good starting point. Thanks. - Ravi_Rajan_7549
Nimbostratus
Hi, - jsudy_47579
Nimbostratus
I'm having the same issue and here is what I have found in troubleshooting so far: - jasonpsmith_408
Nimbostratus
I have a similar issue. IIS6 win2003, 2 servers in a round robin. - hoolio
Cirrostratus
Which LTM version are you running? If you disable OneConnect on the VIP, do you still see the issue?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects