Forum Discussion
User Logout request deny???
Looks like you are doing an AD auth or AD query called 'CEO AD Query' for the user 'adil.test', which is not successful and then goes to 'fallback' branch in the APM VPE flow, ending to 'Deny' endpoint. Thus denying the logon and closing/deleting the session.
Your credentials may not be correct or the AAA (AD) server may not be properly configured in BIG-IP Access Policy. Have you set the proper credentials for the AD server in Access Policy AAA config? AD query needs credentials whilst AD Auth may not. These came to my mind first.
You may need to troubleshoot a bit more. If you haven't done yet, you can set the logging level for Access Policy to debug level (System->Logs->Configuration: Access Policy Logging). Try to log in to the virtual server again and then run an Access Policy all sessions report, and there clicking the correct session ID link in the report list, to see the flow in more detail for troubleshooting. The debug level reveals the whole flow in detail. You will also see all relevant APM session variables and their values.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com