firepass
14 TopicsAPM - configure local ip / port of App tunnel
is it possible to configure the local ip and local port for an App tunnel? like it was possible in the Firepass. or is this something which is determined by the software and can't be configured? from some test i usually get the ip 127.0.0.5 and sometimes a port number 1 higher then the destination port.557Views0likes7CommentsProblem Login Firepass with the Client API
Hi, I'm trying to use the Firepass client via the f5fpapi dll and I have issues with it. When I call OpenSession, I receive the _IAppTunnelEventsEx_OnOpenSessionFailedEventHandler event with the message "Access is denied" and the error 0x80070005. The authentication is made by certificate and I have to choose it after the OpenSession so I reached the server. When I use the CLI client with the same parameters I have no problem. I don't know if it's an issue in my code or in the server configuration. Does anyone already had this problem ? Thanks329Views0likes1CommentFirePass - java.lang.NoClassDefFoundError: F5JApplet
We need to maintain a system that uses FirePass and need to add an applet to one of the applications that is accessed via FirePass. When the applet is accessed directly everything is ok, but when accessed via FirePass we see the error: java.lang.NoClassDefFoundError: F5JApplet at java.lang.ClassLoader.defineClass1(Native Method) at java.lang.ClassLoader.defineClass(Unknown Source) at java.security.SecureClassLoader.defineClass(Unknown Source) at java.net.URLClassLoader.defineClass(Unknown Source) We realise that FirePass re-writes the Java byte code and have tried switching that off, but we then get issues with the applet not being able to resolve some of the URLs. Are there any additional libraries that need to be installed on the client? Or how are the F5Applet, F5Socket classes supposed to be added? Appreciate any help Ka285Views0likes1Commentsha256 signed client certs on Firepass
Due to the sunsetting of browser support for certs signed with sha1 I thought it would be a good time to look at issuing new VPN user certificates with sha256 sigs instead. In testing I've found my Firepass does not seem to like the sha256 signed certs. I checked the KB and searched around here and didn't find anything on the topic. Anyone have any feedback? I know VPN client certs aren't at issue with the browser support for sha1 signed web server certs, but it was on my brain and I liked the consistency approach.313Views0likes4CommentsWindows 7, IE10, F5 Protected Workspace and Firepass suddenly stopped working
Hi I am an end user of the F5 firepass VPN solution to enable me to connect to my work PC via Remote Desktop using a Protected Workspace. I know that there are a number of articles written about this on the F5 site but I was not able to find one which covers my situation. My firepass was working and the after one window update it stopped working, I have uninstalled the update but it still doesn't work. When I try it switches to the Protected Workspace correctly but does not spawn an IE session to carry on so that I can enter my login details. Also if I try and open an IE session in the Protected workspace it opens on the base machine outside of the Protected Workspace. I have tried uninstalling all F5 components and doing the install again but it has not worked. I have tried in IE and firefox and it's same error. I checked the logs and I can see the following error in f5dsklog file \main.cpp, 1085, HandlePwsCmd, Failed to wait for parent process to exit before launching a browser. Please help. Not sure if I'm asking in the right forum, please move if it's not supposed to be here. Thanks278Views0likes1CommentDNS issues while on Firepass
Hi, We are having an issue with clients connecting to the firepass and registering with DNS. Once on the vpn the client does not have any issues accessing internal or external recourse via fqdn or anything like that but.... If you do an nslookup or ping by hostname it returns the ip address of the users local network with a no response. For instance, if I ping my computer by hostname it returns 192.168.1.x but my vpn address is 10.61.26.x. We do quite a few things such as push software, maintain local admin passwords, auditing etc via hostname and none of that works while users are on firepass because of this issue. We have lots of users that work 100% of the time on vpn. I'm hoping this is just a simple client side issue but at this point I'm pretty stumped. Any help would be greatly appreciated! Thanks252Views0likes2CommentsPublishing Team Foundation Server over SSL VPN
I'm working with a client who is using an F5 FirePass SSL VPN. They are trying to publish Team Foundation Server over the SSL VPN for remote access through Visual Studio. It seems like something an application tunnel should be able to do. Is there any guidance on publishing web services such as TFS through the SSL VPN that can be accessed by desktop applications (in this case Visual Studio)?305Views0likes2CommentsWindows 7, IE11, F5 Protected Workspace and Firepass not always working, Please help.
Hi all I am an end user of the F5 firepass VPN solution to enable me to connect to my work PC via Remote Desktop using a Protected Workspace. I have a question about Windows 7 and IE11, F5 Protected Workspace and Firepass. I know that there are a number of articles written about this on the F5 site but none of them cover exactly my situation. I have two machines one works just fine and the other does not and I can't work out the difference, so wondered if anyone else has solved this? The first machine that works fires up the Protected Workspace correctly then spawns an IE session to run the firepass connection in and connects, happy days. The Second machine that does not work fires up the Protected Workspace correctly but does not spawn an IE session to carry on. Also if I try and open an IE session in the Protected workspace it opens on the base machine outside of the Protected Workspace. I have found a work-around using Firefox, but this involved ignoring error messages and reloading pages, so it is not very end user friendly. I would like all my machines to work like the one I have that works simply. Thanks all Tim423Views0likes1Comment