Forum Discussion

Matt_222037's avatar
Matt_222037
Icon for Nimbostratus rankNimbostratus
Sep 15, 2015

SWG DC client for transparent user identification

Hi there,

 

Looking for some answers on the set up of the DC Agent for transparent user identification for SWG. Apparently there is a need to use the IF-MAP iapp for this, which I have setup and is ready to configure. But when I do it comes back with this error which I cannot find any information on..."SSL forward proxy feature state on clientssl profile(s) and/or serverssl profile(s) doesn't match on virtual server (/Common/IF-MAP.app/IF-MAP)

 

Any answers on this error?

 

Thanks

 

5 Replies

  • mikeshimkus_111's avatar
    mikeshimkus_111
    Historic F5 Account

    Hi Matt, the IF-MAP iApp only deploys a client SSL profile, which doesn't have SSL forward proxy enabled on it. That error message sounds more like what you might get if you were running the SWG iApp and selected a pre-existing client or server SSL profile with mismatched forward proxy settings.

     

    Can you tell me what you chose for your inputs in the iApp?

     

    thanks

     

  • Hi Mike,

     

    I didnt use the SWG iApp for this, I just set it up directly. The IF-MAP iApp only requires you to select a VIP address and some keys.

     

    Would I be better off using the SWG iApp?

     

    Cheers

     

    • mikeshimkus_111's avatar
      mikeshimkus_111
      Historic F5 Account
      For sure, the SWG manual config is a prime example of why we use iApps.
  • You need a fresh install without any legacy SWG config for this to work.

     

    I reset the box to default, installed the IF-MAP iApp, which worked first go, then put the SWG iApp on after.

     

  • You need a fresh install without any legacy SWG config for this to work.

     

    I reset the box to default, installed the IF-MAP iApp, which worked first go, then put the SWG iApp on after.