AEM portal access fails with 504 Gateway Timeout after Okta authentication

This article explains how to resolve 504 Gateway Timeout errors that occur after Okta authentication when accessing an Adobe Experience Manager (AEM) application portal. The portal fails to load after authentication, returning a 504 Gateway Timeout error. Update the Application Gateway or load balancer allowlist to include the required CDN provider IP ranges.

Description description

Environment

Adobe Experience Manager (AEM) application portals using Okta authentication and a CDN provider in front of an Application Gateway or load balancer.

Issue/Symptoms

  • Authentication through Okta completes successfully, but the redirect to the AEM application portal fails.
  • Affected individuals receive a 504 Gateway Timeout error.
  • The issue occurs in specific geographic regions.
  • The issue occurs after changes to the allowlist configuration on the Application Gateway or load balancer.

Root cause

Requests from certain CDN provider IP ranges are not allowlisted at the Application Gateway or load balancer, causing legitimate traffic to be blocked and resulting in login failures and 504 Gateway Timeout errors.

Resolution resolution

Follow the steps below to resolve the issue.

  1. Identify the IP ranges for blocked requests on the Application Gateway or load balancer by reviewing HAR files or server logs and determining the source IP addresses of failed requests.
  2. Confirm that these IP ranges correspond to legitimate sources, such as CDN provider edge nodes.
  3. Update the Application Gateway or load balancer configuration to allowlist the required CDN provider IP ranges.
  4. Validate that affected individuals from previously impacted regions can access the AEM application portal and complete the sign-in process successfully.
  5. Monitor access logs to ensure that no additional legitimate requests are blocked.
recommendation-more-help
experience-cloud-kcs-help-kbarticles