For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

mr_evil_116524's avatar
mr_evil_116524
Icon for Nimbostratus rankNimbostratus
Jul 13, 2013

Two-Factor Authentication APM

Hello All,

 

I have tried to follow the instruction below :

 

https://devcentral.f5.com/tech-tips/articles/two-factor-authentication-with-google-authenticator-and-apm.UeHXyqx2uYE

 

However no matter what I do I am always getting "You have entered invalid credentials. Please try again."

 

I know my connection to AD is working fine as I do have another VS which is connected to AD_Auth and I can authentication however for this (two factor auth) I am unable to get any successful result.

 

 

I have looked at the logs and found the following entries :

 

Username 'test_auth'

 

Logging Agent: User failed Google Authenticator Code verification

 

Following rule 'fallback' from item 'Log - failed attempt' to terminalout 'Failure'

 

Following rule 'Failure' from item 'Google Auth verification' to terminalout 'Failure'

 

Following rule 'Failure' from item 'AD auth and Google Auth verification' to ending 'Redirect to error logon page'

 

Access policy result: Redirect_Deny

 

Session deleted due to user logout request.

 

 

Can someone here please help me?

 

 

Thanks

 

 

5 Replies

  • George_Watkins_'s avatar
    George_Watkins_
    Historic F5 Account
    Did it end up being that the clocks were out of sync? Token verification will be unreliable if the clocks are off even the slightest bit.

     

     

    Hope that helps,

     

     

    George
  • No it was something else (didnt assing the iRule to VS).... btw it APM log tuned on by default or something that users will need to turn on or off?

     

     

  • Sorry didn't see this update. The issue was I didnt assign the iRULE to the VS. Once I assigned the iRule it started to work.