Security

Splunk Single Sign-On With F5 Big-IP

da7rutrak
Explorer

I am curious if anyone has attempted to or is currently using an F5 Big-IP LTM as a reverse proxy for Splunk web. I've consulted Google U, but haven't been successful.

alacercogitatus
SplunkTrust
SplunkTrust

So apparently there is some interest in this. 😄

Here's how I have done it:

First - Setup Authentication to LDAP/AD in Splunk. Make Sure you have the right authorization settings.
Second - Setup The SSO configuration options in Splunk

SSOMode = permissive
trustedIP = <your-snat-pool-IPs>
remoteUser = <HEADER THAT CONTAINS USERNAME>

Third - Setup the F5 VIPs normally, with the Splunk Search heads as the pool. Using what ever SSO software you want (we used OAM), make sure you set the header that corresponds with the remoteUser setting.

Boom, done! There really is more than that, but this are the simplest steps I could think up.

Questions?

jkommeri
Explorer

I am also interested in using Big-IP for the same purpose. Though, I am not a network expert. Can you elaborate this "Using what ever SSO software you want (we used OAM)" part a bit more?

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

If you are still interested in this - respond back - I've done it.

kbaldwin
Engager

Interested as well. Getting ready to use F5 for SSO with a single search head and ultimately looking to have Splunk mobile traffic pass thru an F5 VS as well.

da7rutrak
Explorer

@alacerogitatus - yes, still interested. I suspect it requires the ASM, but please share!

0 Karma

dandaily
Explorer

I am very interested in this option. I have an F5 load balancer in front of my search head cluster., and I am looking to configure SSO.

0 Karma

stemo76
Explorer

I too would like to know. We use an F5 to load level across 4 search heads. Would be nice to enable SSO.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...