Forum Discussion
The client's IP address changed while the session was in progress.
SAML Authentication Error
Your session cloud not be established
The client's IP address changed while the session was in progress.
I have disabled this option on the APM Profile (issue fixed).
Select the Restrict to Single Client IP check box to restrict the current session to a single IP address. This setting associates the session ID with the IP address. You must select the associated Custom check box before you can configure this setting. With this setting enabled, upon a request to the session, if the IP address has changed, the request is redirected to a logout page, the session ID is deleted, and a log entry is written to indicate that a session hijacking attempt was detected. If such a redirect is not possible, the request is denied and the same events occur.
- Sajid
Cirrostratus
I have disabled this option on the APM Profile (issue fixed).
Select the Restrict to Single Client IP check box to restrict the current session to a single IP address. This setting associates the session ID with the IP address. You must select the associated Custom check box before you can configure this setting. With this setting enabled, upon a request to the session, if the IP address has changed, the request is redirected to a logout page, the session ID is deleted, and a log entry is written to indicate that a session hijacking attempt was detected. If such a redirect is not possible, the request is denied and the same events occur.
- youssef1
Cumulonimbus
Hi,
yes indeed I already had this problem, disabling this option on the APM Profile will fix your problem.
however, keep in mind that this feature helps protect you from "Session hijacking" if you have an audit this is a point that the auditor can go back up.
in general we encounter this type of problem if the user is in rooming, it changes wifi, or it passes on the 4g.
but given the functionality it's normal behavior ...
regards
- Sajid
Cirrostratus
Hi Youssef,
You are right, user faced same issue during roaming.
is it possible to kill the existing or previous session, in case IP change?
Regards,
Sajid
- youssef1
Cumulonimbus
Hi Sajid,
No, that's not possible. If the user's IP changes it is disconnected and must authenticate again.
I set up certificate authentication, so it's transparent for users because they don't have to enter these credentials...
regards
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com