For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Brice_B_180791's avatar
Brice_B_180791
Icon for Nimbostratus rankNimbostratus
Dec 22, 2014

Try to use APM with basic Basic Auth wihtout to be redirect to logout

Hello

 

I try to implement a end-user basic authentication mechanisme using a BIG-IP as a reverse proxy (BIG-IP 11.4.1 Build 608.0 Final) . I use this https://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-aaa-auth-config-11-4-0 Manuel as template using only basic branche but I alway get a response 302 redirecting to /my.logout.php3?errorcode=19

 

I looking for some way to prevent this redirect and to be prompt with the basic authentication on the end-user browser.

 

have some one an idea ?

 

Thanks.

 

Brice

 

8 Replies

    • Brice_B_180791's avatar
      Brice_B_180791
      Icon for Nimbostratus rankNimbostratus
      using an Irules to set client-less mode : when HTTP_REQUEST { HTTP::header insert "clientless-mode" 1 } I got a error : Access was denied by the access policy. This may be due to a failure to meet access policy requirements. and be redirect to /vdesk/hangup.php3
    • boneyard's avatar
      boneyard
      Icon for MVP rankMVP
      have you check your access policy > reports to see what it says about the session? are the correct profiles attached to the virtual server?
    • Brice_B_180791's avatar
      Brice_B_180791
      Icon for Nimbostratus rankNimbostratus
      I check the report and I got the trace below. regarding the profiles : a simple http profile is attached to the VS and the Access profile with the HTTP 401 + ldap auth: log_tid,log_seq,param_0,param_1,param_10,param_11,param_12,param_13,param_14,param_15,param_16,param_17,param_18,param_19,param_2,param_20,param_21,param_22,param_23,param_3,param_4,param_5,param_6,param_7,param_8,param_9,time_stamp,date_time,log_id,partition "0","1418914323","","Mozilla%2f5.0%20(Windows%20NT%206.1%3b%20WOW64)%20AppleWebKit%2f537.36%20(KHTML%2c%20like%20Gecko)%20Chrome%2f39.0.2171.95%20Safari%2f537.36","","","","","","","","","","","","","","","","","","","","","","","1420560329","2015-01-06 17:05:29"," Received User-Agent header: Mozilla%2f5.0%20(Windows%20NT%206.1%3b%20WOW64)%20AppleWebKit%2f537.36%20(KHTML%2c%20like%20Gecko)%20Chrome%2f39.0.2171.95%20Safari%2f537.36.","PA_Int_RProxy" "0","1418914324","","Mozilla","","","","","","","","","","","5","","","","","Win7","unknown","Full","1","0","1","","1420560329","2015-01-06 17:05:29"," Received client info - Type: Mozilla Version: 5 Platform: Win7 CPU: unknown UI Mode: Full Javascript Support: 1 ActiveX Support: 0 Plugin Support: 1","PA_Int_RProxy" "0","1418914325","","10.198.49.19","","","","","","","","","","","","","","","","","","10.198.36.205","/PA_Int_RProxy/policy_int_gene_vs","Unknown","","","1420560329","2015-01-06 17:05:29"," New session from client IP 10.198.49.19 (ST=/CC=/C=) at VIP 10.198.36.205 Listener /PA_Int_RProxy/policy_int_gene_vs (Reputation=Unknown)","PA_Int_RProxy" "0","1418914326","\N","","","","","","","","","","","","","","","","","","","","","","","","1420560329","2015-01-06 17:05:29","\N: Session deleted due to user logout request.","PA_Int_RProxy" "15834","1419262208","","fallback","","","","","","","","","","","HTTP 401 Response","","","","","Deny","","","","","","","1420560329","2015-01-06 17:05:29"," Following rule 'fallback' from item 'HTTP 401 Response' to ending 'Deny'","PA_Int_RProxy" "15834","1419262209","","Logon_Deny","","","","","","","","","","","","","","","","","","","","","","","1420560329","2015-01-06 17:05:29"," Access policy result: Logon_Deny","PA_Int_RProxy" "0","1418914328","","0","","","","","","","","","","","0","","","","","","","","","","","","1420560363","2015-01-06 17:06:03"," Session statistics - bytes in: 0, bytes out: 0","PA_Int_RProxy"
    • Brice_B_180791's avatar
      Brice_B_180791
      Icon for Nimbostratus rankNimbostratus
      using an Irules to set client-less mode : when HTTP_REQUEST { HTTP::header insert "clientless-mode" 1 } I got a error : Access was denied by the access policy. This may be due to a failure to meet access policy requirements. and be redirect to /vdesk/hangup.php3
    • boneyard's avatar
      boneyard
      Icon for MVP rankMVP
      have you check your access policy > reports to see what it says about the session? are the correct profiles attached to the virtual server?
    • Brice_B_180791's avatar
      Brice_B_180791
      Icon for Nimbostratus rankNimbostratus
      I check the report and I got the trace below. regarding the profiles : a simple http profile is attached to the VS and the Access profile with the HTTP 401 + ldap auth: log_tid,log_seq,param_0,param_1,param_10,param_11,param_12,param_13,param_14,param_15,param_16,param_17,param_18,param_19,param_2,param_20,param_21,param_22,param_23,param_3,param_4,param_5,param_6,param_7,param_8,param_9,time_stamp,date_time,log_id,partition "0","1418914323","","Mozilla%2f5.0%20(Windows%20NT%206.1%3b%20WOW64)%20AppleWebKit%2f537.36%20(KHTML%2c%20like%20Gecko)%20Chrome%2f39.0.2171.95%20Safari%2f537.36","","","","","","","","","","","","","","","","","","","","","","","1420560329","2015-01-06 17:05:29"," Received User-Agent header: Mozilla%2f5.0%20(Windows%20NT%206.1%3b%20WOW64)%20AppleWebKit%2f537.36%20(KHTML%2c%20like%20Gecko)%20Chrome%2f39.0.2171.95%20Safari%2f537.36.","PA_Int_RProxy" "0","1418914324","","Mozilla","","","","","","","","","","","5","","","","","Win7","unknown","Full","1","0","1","","1420560329","2015-01-06 17:05:29"," Received client info - Type: Mozilla Version: 5 Platform: Win7 CPU: unknown UI Mode: Full Javascript Support: 1 ActiveX Support: 0 Plugin Support: 1","PA_Int_RProxy" "0","1418914325","","10.198.49.19","","","","","","","","","","","","","","","","","","10.198.36.205","/PA_Int_RProxy/policy_int_gene_vs","Unknown","","","1420560329","2015-01-06 17:05:29"," New session from client IP 10.198.49.19 (ST=/CC=/C=) at VIP 10.198.36.205 Listener /PA_Int_RProxy/policy_int_gene_vs (Reputation=Unknown)","PA_Int_RProxy" "0","1418914326","\N","","","","","","","","","","","","","","","","","","","","","","","","1420560329","2015-01-06 17:05:29","\N: Session deleted due to user logout request.","PA_Int_RProxy" "15834","1419262208","","fallback","","","","","","","","","","","HTTP 401 Response","","","","","Deny","","","","","","","1420560329","2015-01-06 17:05:29"," Following rule 'fallback' from item 'HTTP 401 Response' to ending 'Deny'","PA_Int_RProxy" "15834","1419262209","","Logon_Deny","","","","","","","","","","","","","","","","","","","","","","","1420560329","2015-01-06 17:05:29"," Access policy result: Logon_Deny","PA_Int_RProxy" "0","1418914328","","0","","","","","","","","","","","0","","","","","","","","","","","","1420560363","2015-01-06 17:06:03"," Session statistics - bytes in: 0, bytes out: 0","PA_Int_RProxy"