MobileSafe
20 TopicsLTM reverse proxy for Lync security capabilities
Hello we are planning to use LTM as reverse proxy for lync mobile, however I can't find any document explaining how LTM is making lync more secure, is LTM able to detect DDOS attack and to prevent account lockout? Thanks for your helpSolved475Views0likes8CommentsActiveSync don't work correctly for iphone mobile device
Hi, we have deployed last year an iapp exchange2010 that works well for all : owa, rpc, outlook anywhre, autodiscover and ActiveSync. now we have experiencing an issue with mobile device like iphone that is disconnected from ActiveSync somethimes without reason. (i see also that load balacing just for ActiveSync not works fine : 2 servers from 4 that don't receive match traffic like the other) thank you for your help. F5 version 11.4.1 HF9 see bellow the configuration : ltm pool /Common/EXchange_CAS.app/EXchange_CAS_combined_vs_as_pool { app-service /Common/EXchange_CAS.app/EXchange_CAS load-balancing-mode least-connections-member members { /Common/172.21.151.32:443 { address 172.21.151.32 } /Common/172.21.151.33:443 { address 172.21.151.33 app-service /Common/EXchange_CAS.app/EXchange_CAS } /Common/172.21.151.34:443 { address 172.21.151.34 } /Common/172.21.151.35:443 { address 172.21.151.35 } } monitor /Common/EXchange_CAS.app/EXchange_CAS_combined_vs_https_monitor } ltm rule /Common/EXchange_CAS.app/EXchange_CAS_combined_vs_persist_iRule { app-service /Common/EXchange_CAS.app/EXchange_CAS when HTTP_REQUEST { switch -glob [HTTP::path] { "/Microsoft-Server-ActiveSync*" { Direct all ActiveSync clients to a common pool; use HTTP cookie persistence persist cookie pool EXchange_CAS_combined_vs_as_pool } "/rpc/rpcproxy.dll" { Grab all requests for Outlook Anywhere; the following checks assign correct persistence methods. switch -glob [HTTP::header "User-Agent"] { "MSRPC" { This User-Agent section matches most versions of Outlook and Windows using Outlook Anywhere. The OutlookSession cookie is new to Outlook 2010. if { [HTTP::cookie exists "OutlookSession"] } { persist uie [HTTP::cookie "OutlookSession"] 3600 } else { persist uie [HTTP::header "Authorization"] 3600 } } "*Microsoft Office*" { This section matches some versions of Outlook 2007 on Windows XP persist uie [HTTP::header "Authorization"] 3600 } default { This section catches all other requests for Outlook Anywhere, and sets a persistence method that does not require the client to support HTTP cookies persist source_addr } } Finally, this assigns the Outlook Anywhere pool and turns off full HTTP parsing and compression. If the preceding clients should be sent to separate pools, the pool statement should be removed here, and a separate pool statement placed in each of the preceding logic branches. Other modules (APM, ASM, etc.) should be disabled here as well, if active for other traffic though this virtual server. pool EXchange_CAS_combined_vs_oa_pool CACHE::disable HTTP::disable COMPRESS::disable } "/xml/autodiscover.aspx" { Requests for Autodiscovery information. The selected pool might be unique, or might be the same as e.g. your pool for OWA or ActiveSync. In this example, we use the same pool that receives ActiveSync traffic. persist cookie pool EXchange_CAS_combined_vs_ad_pool } default { This final section takes all traffic that has not otherwise been accounted for and sends it to the pool for Outlook Web App persist cookie pool EXchange_CAS_combined_vs_owa_pool } } } } ltm virtual /Common/EXchange_CAS.app/EXchange_CAS_combined_vs_https_virtual { app-service /Common/EXchange_CAS.app/EXchange_CAS destination /Common/172.21.150.100:443 fallback-persistence /Common/EXchange_CAS.app/EXchange_CAS_source_address_persistence_profile ip-protocol tcp mask 255.255.255.255 persist { /Common/EXchange_CAS.app/EXchange_CAS_cookie_persistence_profile { default yes } } profiles { /Common/EXchange_CAS.app/EXchange_CAS_combined_vs_caching_profile { } /Common/EXchange_CAS.app/EXchange_CAS_combined_vs_clientssl { context clientside } /Common/EXchange_CAS.app/EXchange_CAS_combined_vs_http_profile { } /Common/EXchange_CAS.app/EXchange_CAS_combined_vs_oneconnect { } /Common/EXchange_CAS.app/EXchange_CAS_combined_vs_serverssl { context serverside } /Common/EXchange_CAS.app/EXchange_CAS_combined_vs_wan-optimized-compression_profile { } /Common/EXchange_CAS.app/EXchange_CAS_lan-optimized_tcp_profile { context serverside } /Common/EXchange_CAS.app/EXchange_CAS_wan-optimized_tcp_profile { context clientside } /Common/ntlm { } } rules { /Common/EXchange_CAS.app/EXchange_CAS_combined_vs_owa_append_iRule /Common/EXchange_CAS.app/EXchange_CAS_combined_vs_persist_iRule /Common/Exchange_hsts_ltm } source 0.0.0.0/0 source-address-translation { type automap } translate-address enabled translate-port enabled }425Views0likes5CommentsF5 load balancer for restful and jsession ID cookie based persistence
Hi guys , I have two tomcat nodes server running separately on two different VM's but in same vlan. These two nodes are behind f5 load balancer with jsession cookie based persistency on port 80. While SSl session Id based persistency on secure port 443. Each of the nodes run websites and have their own jsessionID unique to itself. Hence the reason why above persistency is working perfectly for it. But their are restful webservices running on each of these nodes within same tomcat server instance along with website. Each of the webservice use oauth2 based authentication mechanism. These webservices are directly consumed by Android and iOS application. Now since restful services are neither governed by jSession Cookie based persistency nor ssl session id based persistency. Each time when i hit the load balancer through mobile app with secure webservices it randomly redirects the request to either node 1 or node 2. Since for each webservice hit ssl session id is different. The above scenario happens. What configuration needs to be done at f5 level to ensure the webservices are appropriately redirected399Views0likes1CommentOutlook Mobile App not working through LTM
dears , i have confirmed exchange server 2016 manually in LTM , didn't used the iAPP , everything is working perfectly i mean the webmail and the computer outlook application and only outlook mobile App is not working. we already allowed /Microsoft-Server-ActiveSync in the allowed URL list but still we are not capable of either receiving or sending emails through mobile app. note that ASM is also enabled.388Views0likes0CommentsDefference between 5050s & 5250v
Hi please tell me the differences between f5 BIG-IP 5250v and 5050v chassis. How should I decide between them? Is this model are in same chassis? The chassis of a 5250v is always of a 5050s and additional features of 5250v as compared to 5050s are unlocked via a soft license upgrade ? Regards Bilash266Views0likes2CommentsHow Companies offers the best life insurance policy in India?
There are several companies offers life insurance polices such as Bajaj Allianz Life, icici Pru life, SBi life and so on. It depends which company is preferable for an person. I guess each one should look upon certain criteria such as claim settlement ratios, company background and highest policy seller and so on.248Views0likes1Comment