Forum Discussion

Martin_Vlasko's avatar
Martin_Vlasko
Icon for Altocumulus rankAltocumulus
Oct 23, 2015

Edge Client client-side checks - What exactly is done on client's PC?

Hi,

 

I am struggling to find detailed information about what exactly the F5 Edge Client is doing on remote client's PC when client-side checks, for example 'firewall check' is configured and run by the APM policy.

 

The firewall check is as simple as 'Windows Firewall of any version must be turned on'.

 

From time to time, we experience problems with some users who suddenly cannot use remote access because the 'firewall check' is suddenly failing, although their Windows Firewall is turned on. (and they had no issues before).

 

I don't believe it is a problem of the actual windows firewall. I assume that something must have been changed on the client's PC which somehow prevents the Edge Client to perform this client-side check. All I was able to find in F5 documentation is that these client-side checks use ActiveX to perform their checks.

 

Do you know what exactly must be allowed / turned on / configured on the client PC in order to successfully run these client-side checks? What (process, service, files?) and how (activeX, plugins?) is the Edge Client executing its checks? Can I maybe find some error message in Edge Client logs helping to understand this behavior somewhere? Because the APM's logs are not useful.

 

Thanks, Martin

 

2 Replies

  • Lucas_Thompson_'s avatar
    Lucas_Thompson_
    Historic F5 Account

    We've had a few reports of specifically Widows Firewall Check intermittent behavior with the OPSWAT library we (and other vendors) OEM for use in device posture checks. This is a 3rd party component we include, so source code is not available to us. It's essentially a black box. Please open a support ticket for further analysis, there are some tools that can be used to help diagnose OPSWAT.

     

    Any information like what client PCs are affected and how often the checks fail would be helpful. More testing will be needed, so make sure you have a few test PCs available to you.

     

    • Martin_Vlasko's avatar
      Martin_Vlasko
      Icon for Altocumulus rankAltocumulus
      Hi, Thanks for the tip. I already opened the support ticket but was hoping that perhaps somebody on devcentral will reply quicker :-) let's see what the support team responds.