Forum Discussion
SAML configuration with LTM exposed app
Dear all,
I need to expose an internal web application from my BigIP but I don't want to expose directly the application logon page. The developer said to me that it can support SAML so I was thinking to implement it on my F5. I don't understand what is the best configuration I can use, do I need both IDP and SP configured on the BigIP? Because if I configure it only as IDP the users need to access the application homepage before being redirected to the IDP, am I wrong?
Thank you in advance
Luca
- Dave_W
Employee
Hello Luca, this depends. In this use case it does sound like APM would be the SP. You could have the APM be both the IdP and SP (or use an external IdP). Regarding your last question, no, typically SAML can be SP or IdP initiated. So they could go to the App (SP) first or the IdP first.
Here is some more info:
https://www.youtube.com/watch?v=WdRJZ5BnZug
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com