APM Configuration to Support Duo MFA using iRule
Overview
BIG-IP APM has supported Duo as an MFA provider for a long time with RADIUS-based integration. Recently, Duo has added support for Universal Prompt that uses Open ID Connect (OIDC) protoco...
Updated Mar 01, 2025
Version 8.0Hardeep_Kaur
I document user guides, online help, and release notes for F5's BIG-IP APM, F5 Access Apps, and Edge Client products. I also work on Access Guided Configuration online help and compatibility matrices.Ret. Employee
delv3chio
Employee
Joined May 20, 2019
Jerrod_Kimbler
Employee
Vintage F5 Employee, Est. 2006varunmuthusamy
Nimbostratus
Jun 14, 2021Hi
I am trying to set this up for a webtop. I am on version 16.0.11 Build 0.9.6. I authenticate using LDAP first then use the irule event and oauth client before assigning the resources. After successfully authenticating to LDAP, I get redirected to the Duo portal with the error " {"error": "invalid_client", "error_description": "The supplied client_assertion is not a valid JWT"} " I have double-checked my configuration and looks ok. so not sure what I am missing. can you help?
Thanks
Varun