Forum Discussion
ADFS Proxy, APM, ASM Craziness
- Nov 04, 2022
Ah got it as it seems like some guided configs F5 is using an internal iApp LX based on node js to make this magic and probably 404 is configured there.
It could be a url filter or layer 7 access list in the APM session policy or if there is a per-request policy. You can also enable APM HSM logging to try to see the APM logs that block this:
https://support.f5.com/csp/article/K45423041
See at the end of this link about HSM with APM:
ASM can use the APM session id for user session matching:
As your APM is before the ASM you can also place the ASM before the APM to protect the login page or webtop if you use those. But in this case maybe the session feature will not work as the APM will be after the ASM but still the ASM may track by username by the login page:
https://support.f5.com/csp/article/K13315545
https://support.f5.com/csp/article/K54217479
I created a test adfs config and I take my words back as by default the ADFS config shouldn't provide any URL protections but if you modified it and if the ASM/Advanced WAF is the one doing this as it could block without returning custom page if someone has made it so.
ADFS config with APM authentication and F5 SMS OTP:
- JustCooLpOOLeNov 03, 2022
Cirrocumulus
We're working with support on this issue but there is no APM policy that is in use for ADFS. We are using the ADFS Trust portion that shows on a Virtual Server where you enter in Domain Admin creds to establish the trust and a certificate is autorenewed with the ADFS servers. That's where you see that anything which does not include a "/adfs" is presented with a 404. No ASM policy is in play.
- Nikoolayy1Nov 04, 2022
MVP
Ah got it as it seems like some guided configs F5 is using an internal iApp LX based on node js to make this magic and probably 404 is configured there.
- JustCooLpOOLeNov 10, 2022
Cirrocumulus
Definitely a nice feature but if you're trying to put an AWAF policy in front, the violations are never triggered. Looking into having a virtual server placed in front of the ADFS virtual server but that is challenging too
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com