For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

f5learn_164388's avatar
f5learn_164388
Icon for Nimbostratus rankNimbostratus
Aug 13, 2014

regarding edgeclient vpn and iis website setup for windows authentication

On Ipad I have EdgeClient. VPN connection is established from Ipad. When trying to access the website hosted on IIS 7.0 which is setup for windows authentication, I get a logon dialog on the Ipad. Once logged on with credentials, able to access the website. Now closed the browser and tried accessing same site and it does not show the logon screen, which is good.

 

Bu my question is, is there a way I can get the logon dialog to not show up the first time since VPN connection is already established. Any references to KB will be appreciated.

 

4 Replies

  • Hello,

     

    there is a configuration that can fit your need.

     

    You can configure a new VS that point out to your iis web server. You attach an access profile to this VS. The access profile should have only a vpe with "start-allow". You can attach an sso profile to this access profile.

     

    Thus, once you are authenticated with your edge client, if you try to access this VS, the APM will do sso on your web app using credentials from the edge client session.

     

    One requirement is to prompt user for valid credentials at the login.

     

    You can find a kb here : http://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-sso-config-11-4-0/6.htmlunique_1287059934

     

    • f5learn_164388's avatar
      f5learn_164388
      Icon for Nimbostratus rankNimbostratus
      Thanks, Yann. I will look into this and respond back with my results.
  • Hello,

     

    there is a configuration that can fit your need.

     

    You can configure a new VS that point out to your iis web server. You attach an access profile to this VS. The access profile should have only a vpe with "start-allow". You can attach an sso profile to this access profile.

     

    Thus, once you are authenticated with your edge client, if you try to access this VS, the APM will do sso on your web app using credentials from the edge client session.

     

    One requirement is to prompt user for valid credentials at the login.

     

    You can find a kb here : http://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-sso-config-11-4-0/6.htmlunique_1287059934

     

    • f5learn_164388's avatar
      f5learn_164388
      Icon for Nimbostratus rankNimbostratus
      Thanks, Yann. I will look into this and respond back with my results.