F5 - Source IP

Goggins, Patrick gogginsp at uwgb.edu
Sun Jan 22 11:15:54 EST 2017


You’ll need to modify the iRule attached to the Virtual Server for your SP’s to inject the X-Forwarded-For entry. On the SP’s, you’ll likely have to modify the logging so that it also logs that header information when it reaches the SP.


~Patrick

From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Lionel Samuel
Sent: Saturday, January 21, 2017 7:44 PM
To: users at shibboleth.net
Subject: F5 - Source IP

Hello:
Has anyone implement F5 where there is load balancing to multiple nodes of SPs?
Were there any challenges in ensuring that the client source IP was transmitted to the SP?

I am not an expert on F5 -- so far the IP received by the SP is not the client's browser -- which will be an issue from maintaining session, security audit etc. Haven't tried the vendor route yet -- hoping for feedback from others who may have faced this previously.
Thanks.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170122/d762199b/attachment-0001.html>


More information about the users mailing list