For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Davo_T_20783's avatar
Davo_T_20783
Icon for Nimbostratus rankNimbostratus
Oct 01, 2014

Using F5 to load balance KDC(s)

Hi - are there any issues with using F5 to load balance a given application's kerberos (port 88 UDP/TCP) requests to a set of KDC? Actually the real requirement is ensure that the application connects to a healthy KDC and so health check would be necessary.

 

1 Reply

  • We've looked at this in the past, and i'm not entirely sure that you can. From our looking, when you send a kerberos packet to a server it sends back the server name, and if it doesn't match what the server is expecting, then the session just breaks. We ended up abandoning the idea.