You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/manage-apps/f5-big-ip-ldap-header-easybutton.md
+10-9Lines changed: 10 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -309,7 +309,7 @@ The **Application Pool tab** details the services behind a BIG-IP that are repre
309
309
310
310
2. Choose the **Load Balancing Method** as *Round Robin*
311
311
312
-
3.Update**Pool Servers**. Select an existing node or specify an IP and port for the server hosting the header-based application
312
+
3.For**Pool Servers** select an existing node or specify an IP and port for the server hosting the header-based application
313
313
314
314

315
315
@@ -384,28 +384,29 @@ At that point, changes via the wizard UI are no longer possible, but all BIG-IP
384
384
385
385
## Troubleshooting
386
386
387
-
You can fail to access the secure hybrid access protected application due to any number of factors, including a misconfiguration.
388
-
389
-
BIG-IP logs are a great source of information for isolating all sorts of authentication & SSO issues. When troubleshooting you should increase the log verbosity level.
387
+
Failure to access a SHA protected application can be due to any number of factors. BIG-IP logging can help quickly isolate all sorts of issues with connectivity, SSO, policy violations, or misconfigured variable mappings. Start troubleshooting by increasing the log verbosity level.
2. Select the row for your published application then **Edit > Access System Logs**
394
392
395
393
3. Select **Debug** from the SSO list then **OK**
396
394
397
-
Reproduce your issue before looking at the logs but remember to switch this back when finished. If you see a BIG-IP branded error immediately after successful Azure AD pre-authentication, it’s possible the issue relates to SSO from Azure AD to the BIG-IP.
395
+
Reproduce your issue, then inspect the logs, but remember to switch this back when finished as verbose mode generates lots of data.
396
+
397
+
If you see a BIG-IP branded error immediately after successful Azure AD pre-authentication, it’s possible the issue relates to SSO from Azure AD to the BIG-IP.
398
398
399
399
1. Navigate to **Access > Overview > Access reports**
400
-
2. Run the report for the last hour to see logs provide any clues. The **View session** variables link for your session will also help understand if the APM is receiving the expected claims from Azure AD
400
+
401
+
2. Run the report for the last hour to see if the logs provide any clues. The **View session** variables link for your session will also help understand if the APM is receiving the expected claims from Azure AD
401
402
402
403
If you don’t see a BIG-IP error page, then the issue is probably more related to the backend request or SSO from the BIG-IP to the application.
403
404
404
-
1. In which case you should head to **Access Policy > Overview > Active Sessions** and select the link for your active session
405
+
1. In which case head to **Access Policy > Overview > Active Sessions** and select the link for your active session
405
406
406
-
2. The **View Variables** link in this location may also help root cause SSO issues, particularly if the BIG-IP APM fails to obtain the right attributes
407
+
2. The **View Variables** link in this location may also help root cause SSO issues, particularly if the BIG-IP APM fails to obtain the right attributes from Azure AD or another source
407
408
408
-
3.The following command from a bash shell validates the APM service account used for LDAP queries and can successfully authenticate and query a user object:
409
+
The following command can also be used from the BIG-IP bash shell to validate the APM service account used for LDAP queries and can successfully authenticate and query a user object:
0 commit comments