Configure the Virtual Service
- Last Updated: June 19, 2025
- 2 minute read
- LoadMaster
- LoadMaster LTSF
- Documentation
Follow the steps below to configure the Virtual Service to use SAML authentication:
- In the main menu of the LoadMaster WUI, go to Virtual Services > Add New.
- Enter a valid IP address in the Virtual Address text box.
- Enter the Port.
- Enter a Service Name.
- Click Add this Virtual Service.
- Expand the ESP Options section.
- Select the Enable ESP check box.
- Select SAML as the Client Authentication Mode.
- Select the SAML SSO Domain.
- Enter any Allowed Virtual Hosts, as needed.
- Enter the Logoff String and click Set SSO Logoff String.Note: The Logoff String is important. The Logoff String has a special protocol flow associated with it in the context of SAML. Not only do you want to log out of the Service Provider on the LoadMaster, but the user also must be logged out of the IdP.
- If required, enter the Additional Authentication Header and click Set Additional Authentication Header.Note: The Additional Authentication Header specifies the name of the HTTP header. This header is added to the HTTP request from the LoadMaster to the Real Server and its value is set to the user ID for the authenticated session.
- Select the Server Authentication Mode.Note: If you select Server Token as the Server Authentication Mode on reception and verification of the SAML response, the LoadMaster requests a long-lived token. The LoadMaster then builds a redirection URL with the token specified.Note: The Server Authentication Mode can be set to None, KCD, or Server Token. Basic Authentication is not supported because the LoadMaster does not have access to the username and password.
- If using KCD as the Server Authentication Mode, please select the relevant option for Server Side configuration. Note: For further information on KCD, refer to the Kerberos Constrained Delegation, Feature Description.
- Configure any other settings as needed.