Technical Forum
Ask questions. Discover Answers.
cancel
Showing results for 
Search instead for 
Did you mean: 

F5 Big-IP Edge Client (uses internet explorer by default?, not compatible with Duo Yubikey Authn)

nicholse
Nimbostratus
Nimbostratus

Good morning,

We use the Big-IP Edge VPN Client and during authentication, we have the Duo MFA inline splash page come up but when selecting Yubikey devices, the message comes up "Requires Chrome, Firefox, Safari, or Edge to use Security Keys". I see that this is part of a rundll process and looks like it is using Internet Explorer. I am curious if there is a way to configure the Big-IP client to use Chrome or Edge instead so that I can use the Yubikey. Weirdly enough I have seen it work in an older or newer version of the Big-IP client but I cant remember how I made it work. Any help would be appreciated! 

nicholse_0-1672433316673.png

 

4 REPLIES 4

nicholse
Nimbostratus
Nimbostratus

A little research suggests that there may be a version of the F5 Big-IP Edge Client that supports Chrome or Edge via Duo's Universal vs. Traditional prompt. See url below. Can anyone verify this? Or do we need to modify the policy somehow to use Universal vs Traditional? As it is, our only choice for getting connected to VPN securely is via the Duo app because we don't allow phone call or sms. @Chris_Zhang ?

https://help.duo.com/s/article/7118?language=en_US

The release notes from 7.2.1 suggest that it shold work?
https://techdocs.f5.com/kb/en-us/products/big-ip_apm/releasenotes/related/relnote-edge-client-7-2-1....

Looks like I am using 7.2.2 yet it doesnt work...

nicholse_0-1672473552692.png

I also tried modifying the IE compatibility keys for rundll32.exe and  f5fpclientW.exe using 2af8 and 2af9 without any luck as referenced here and here:
https://help.duo.com/s/article/7620?language=en_US
https://techdocs.f5.com/kb/en-us/products/big-ip_apm/releasenotes/related/relnote-edge-client-7-2-3....

 





 

Leslie_Hubertus
Community Manager
Community Manager

Hi @nicholse - I think your post got caught in the holiday traffic slump... I've asked one of my teammates to come take a look. 

nicholse
Nimbostratus
Nimbostratus

I got this reply from Duo today. Can anyone coroborate? Is this the only way for us to get the Yubikeys working with F5 Edge Client?
https://duo.com/docs/f5bigip-web
From Duo Support:
"In terms of what F5 Edge Client versions support using those browsers, I am not sure. I will say, if you want to utilize this Universal Prompt with F5 as you mentioned, the best way to do this is F5 BIG-IP APM with OIDC Web Duo Prompt. Note: this does require Big-IP firmware version 13.1 or later."

buulam
Community Manager
Community Manager

Hi @nicholse , from what I'm reading, Duo Support is correct and you'll want to follow that link to get instructions on the configuration.

~~~~~~~~~~~~~~~~~~
@buulam / YouTube.com/DevCentral