In this configuration, F5's BIG-IP APM acts as an Open ID Connect (OIDC) client and Duo acts as an identity provider for two-factor authentication, showing the interactive web-based Duo prompt. Unlike the Duo RADIUS configurations for F5 BIG-IP APM, there is no need to deploy any Duo software on your premises.
Use of Duo as an OIDC provider is supported in BIG-IP versions 13.1, 14.1x, 15.1x, and 16.x. Verify that your BIG-IP is running one of these versions before continuing. If your BIG-IP is at version 11 or 12 and you cannot update, consider use of the Duo RADIUS configuration.
Previously, the Client ID was called the "Integration key" and the Client secret was called the "Secret key".
Migration to Universal Prompt for your F5 BIG-IP APM Web application is a two-step process:
We've already updated the Duo F5 BIG-IP APM Web application hosted in Duo's service to support the Universal Prompt when it's ready, so there's no action required on your part to update the application. The "Universal Prompt" section of this application's details page in the Admin Panel reflects this status today as "Waiting on Duo".
When the Universal Prompt becomes available, you'll return here to activate it for users of this application. The status will change to "New Prompt Ready", and you'll see the control here for turning it on or off. Until then, your users continue to experience the current Duo prompt.
Click the See Update Progress link to view the Universal Prompt Update Progress report. This report shows the update availability and migration progress for all your Duo applications in-scope for Universal Prompt support.
If you're interested in participating in a private preview of the Universal Prompt experience, please apply using this form.
Refer to the article APM Configuration to Support Duo MFA using iRule on F5 DevCentral and follow those step-by-step instructions for adding Duo authentication to your APM logins.
Do not create a WebSDK application as mentioned in the F5 article. Instead use the F5 BIG-IP APM Web application you created earlier.
To test your setup, go to the URL you normally use to log in to your F5 BIG-IP APM in a browser window. After you complete primary authentication at the F5 BIG-IP, you'll be redirected to the Duo Prompt or Duo user enrollment. Completing Duo authentication returns you to the BIG-IP to complete your login.
Need some help? Reach out to Duo Support for assistance with creating the F5 BIG-IP APM Web application in Duo, enrolling users in Duo, Duo policy questions, or Duo authentication approval issues. For assistance configuring or managing your BIG-IP device, please contact F5 Support.