Forum Discussion

Amallet's avatar
Amallet
Icon for Nimbostratus rankNimbostratus
Dec 12, 2019

F5 APM with proxy chaining

Dear all,

I'm trying to implement proxy chaining on the APM infrastructure, for that I used this following documentation: https://techdocs.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-secure-web-gateway-13-0-0/8.html

My infrastructure diagram:

External PC==SSL==>F5(gate)===proxychainning===>LAN PROXY==Proxychaining==>DMZ Proxy==>LAN 2==>Target

I use the Per Request Policy with " Select Proxy " configured on transparent mode. In the log, the flow use this criteria but I do not see the proxy connection being established and it doesn't work.

I tried to add a HTTP Proxy Connect Profile with the state disable but with this option, the Edge client no longer works.

Error message:

tmm1[10056]: 011f0007:3: http1x_process_state_unestablished - Invalid action:0x2043010 serverside (127.1.1.2:3701 -> 44.63.27.10:59389) clientside (X.X.X.X:59389 -> Y.Y.Y.Y:443) (Server side: vip=/Common/VIP_vs profile=http_proxy_connect addr=127.1.1.2 port=3701 rtdom_id=0 server_ip=127.1.1.2)

If someone has already implemented this case, I am interested in your experience or more documentation.

Thank you in advance

1 Reply

  • leea's avatar
    leea
    Icon for Nimbostratus rankNimbostratus

    Access Policy Manager® (APM®) brings these abilities to forward proxy chaining: Offload authentication from and support authentication to the next hop on the client's behalf. Support single sign-on to the next hop and to resources at the next hop.

     

     

    Hope this helps

    Regards worldforpcapp