ADFS Proxy Replacement on F5 BIG-IP
BIG-IP Access Policy Manager can now replace the need for Web Application Proxy servers providing security for your modern AD FS deployment with MS-ADFSPIP support released in BIG-IP v13.1. This arti...
Published Mar 13, 2018
Version 1.0Graham_Alderso1
Employee
Joined May 22, 2019
Graham_Alderso1
Employee
Joined May 22, 2019
Graham_Alderso1
Nov 21, 2018Employee
NPolitis, no, not a simple way. It may be possible with some iRules but the official supported method would continue to be two virtual servers. This also provides you with troubleshooting flexibility you probably don't want to lose.
You can deploy them at the same destination IP address however, and use the source IP constraint on the VS page for the internal load balancing only virtual server, though. You'd constrain it to your internal network, e.g.: 10.0.0.0/8 instead of the default 0.0.0.0/0. You would need to make this source address adjustment manually, outside the iApp with strictness disabled.