F5 Reverse Proxy with MFA



We have a requirement to implement reverse proxy with multifactor authentication. The current network setup has a cloud WAF which forwards traffic to on-premise application LB VIP. F5 support guided me to use APM+LTM in DMZ which will act as revers proxy with mfa.


But from the APM data sheets, it looks more of a SSL VPN. So I am concerned if this solution will work with SSL inspection on the Cloud WAF.


Traffic flow,


External user (HTTPS) >> Cloud WAF (SSL inspection, NAT) >> F5 APM + LTM (Reverse proxy + MFA + SSL offloading) >> Internal LB >> HTTP APP Servers


Can anyone please guide me on this requirement.


    Refer the F5 APM guide here, it can be used as an SSL VPN and also as a authentication proxy, So to answer your question it does support MFA. You can also refer to this article, as an example for MFA


