<html><body><div style="font-family: verdana,helvetica,sans-serif; font-size: 10pt; color: #000000"><div>Thanks Rod<br></div><div><br></div><div><span name="x"></span><div style="text-align: left;" data-mce-style="text-align: left;"><span style="font-size: small;" data-mce-style="font-size: small;" size="2"><span style="font-family: verdana,helvetica,sans-serif;" data-mce-style="font-family: verdana,helvetica,sans-serif;"></span></span>Regards<br></div><br>Simon Bright<br>Technical Services Manager<br>E2BN<br>01462 834588<br>07912 853 107<br><a href="http://www.e2bn.org" data-mce-href="http://www.e2bn.org">www.e2bn.org</a><br><div><br></div><br><span name="x"></span><br></div><hr id="zwchr"><div style="color:#000;font-weight:normal;font-style:normal;text-decoration:none;font-family:Helvetica,Arial,sans-serif;font-size:12pt;" data-mce-style="color: #000; font-weight: normal; font-style: normal; text-decoration: none; font-family: Helvetica,Arial,sans-serif; font-size: 12pt;">&gt; Can anyone advise me how to relax the IDP session filter security to ignore the scenario where the client may be routing via multiple public IP addresses.<br><div><br></div>https://wiki.shibboleth.net/confluence/display/SHIB2/IdPProxyClustering See under “Inhibit the consistent address check”<br><div><br></div>Others are better placed to comment on the security implications of this..<br><div><br></div>/Rod <br><div><br></div><br>--<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div><div><br></div></div></body></html>