Forum Discussion
Eric_Welsh
Nimbostratus
Dec 17, 2018Separate Access Profiles for Different URIs on the Same Domain
Hello DevCentral, long time lurker, first time caller. Let me preface this post with the fact that I am not an F5 wizard, and I am learning a lot of what I am doing as I go (and thanks to the wonderf...
John_Huttley
Employee
Dec 25, 2018Hi,
On the all Access policies involved, have you enabled profile scope "Global"?
This setting prevents a malicious user from establishing a session using one virtual server, and then using that same session to access, potentially without further authentication, another virtual server and the resources behind it.
Profile Gives a user access only to resources that are behind the same access profile. This is the default value.
Virtual Server Gives a user access only to resources that are behind the same virtual server.
Global Gives a user access to resources behind any access profile that has global scope
This might be a quick fix by allowing authorisation to be shared, otherwise it will need a fair bit of plotting out and debugging..
John
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects