Forum Discussion

kj07208_118528's avatar
May 08, 2014

Understanding cross-domain support

I just read in the F5 documentation the following ... Cross-domain support and split domain from username are both enabled.If you enable cross domain support, and enable split domain username at the login page, and then the user enters his user name, such as user@domain.com, Access Policy Manager uses the user@domain.com as the user principal name to authenticate the user against USERNAME.COM domain.

 

Does this mean that my AD domain defined in the AAA server is irrelevant?

 

1 Reply

  • No it is still relevant, imagine a use case where you have have multiple domains with trust relationships. You authenticate to a domain as per the AAA config, but your user belongs to another one.