Forum Discussion
Andy_from_Sandy
Nimbostratus
Aug 22, 2016Unable to add access policy - getting Your session could not be established.
I have version 11.6.0 build 0.0.401 running in VMware workstation version 12 with a lab license.
The other day I added extra VMs and one of them had the same IP address as I was using as the self-ip ...
Cody_Green_1030
Aug 26, 2016Historic F5 Account
By default the APM MRHSession cookie is only allowed over SSL/TLS, which in my opinion is the only secure way to use APM, and not over HTTP. The issue with APM over non-encrypted traffic is a malicious actor can steal your cookie and impersonate your session.
Now, if you absolutely have to use APM over non-encrypted traffic you can disable the Secure cookie option under the SSO/Auth Domains tab (Access Policy -> Access Profiles then SSO/Auth Domains will be on the top menu).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects