Forum Discussion

Frank_Murray_3's avatar
Frank_Murray_3
Icon for Nimbostratus rankNimbostratus
Jan 11, 2019

How to pass single sign-on credentials

Pardon my ignorance- my understanding of big-ip is pretty basic.

 

We have a pair of servers with a web-based application that we are trying to load balance. We users connect directly to the servers, they are authenticated automatically via their AD credentials. But when they connect to the VIP, they get a prompt to login.

 

How can I set up the VIP so the users don't get the login prompt and are authenticated the same as when they connect directly?

 

Thanks

 

3 Replies

  • Hello Frank,

     

    Big-IP has a couple of different ways of configuring SSO, as you can see here. All of these are enabled through F5's access policy module (APM). If you're fresh to APM, F5 has some excellent documentation here.

     

    Feel free to ask if you have any follow-up questions,

     

    Austin

     

    • AMiles_377865's avatar
      AMiles_377865
      Icon for Cirrocumulus rankCirrocumulus

      That definitely complicates the configuration. Check to see that you can't upgrade your license/provision APM on your LTM Big-IPs, as the configuration becomes much easier to implement. That being said, there does seem to be a precedent for SSO without APM that I found on this devcentral post here. I don't know if there are precedents for other auth systems, but perhaps by referencing the different auth systems you can come to a solution.