Forum Discussion
Eric_Brander_27
Nimbostratus
Dec 05, 2007Active Directory (via LDAP) Authentication
I've successfully set up AD Authentication off-loading with the LTM and Client Authentication module. So now in order for a user to hit our intranet site, they will have to have a valid AD account.
But what if I want to have multiple pages with different authorization requirements? www.intranet.com would be ok for anyone to see, but only members of GRP_Accounting should be able to visit www.intranet.com/accounting.
I assume I would create multiple profiles each with its own GROUP DN setting that's apropriate, and then an iRule for each URL? Has anyone done this before or am I simply asking the F5 to do to much and should handle this sort of access control on the web server itself?
TIA,
Eric Brander
2 Replies
- Fahad_A__Bin_Ma
Nimbostratus
can you tell me how you off load the authentication of AD on LTM. can you send me the steps for this. - hoolio
Cirrostratus
Hi fahadabm,
You can find docs on AskF5 which detail the configuration steps. Here is an example for configuring AD authentication for client traffic (as opposed to administrative authentication for the GUI/console) in 9.3:
Manual Chapter: BIG-IP Local Traffic Manager version 9.3 Implementations: Configuring Remote Authentication for Application Traffic (Click here)
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
