Forum Discussion
APM - How to assign user specific lease pool to network access policy?
We need to implement our vpn policy on APM network access policy.
Our security policy states, each individual person needs to be assigned with an individual user account and an individual ip address. As far as I understand the APM network this results in individual pool configuration along with individual profiles.
Would anyone have faced this requirement too? Would there be a dynamic assignment with say radius authorization or user mapping to reduce the amount of profiles in APM?
Any suggestions welcome!
2 Replies
- iaine
Nacreous
Are you able to query AD...? If so, you could store the IP address in the user object as a custom attribute. Then, as part of the login sequence, query AD to extract the IP and then use that as the client IP
- Cay_Jeglinski_1
Nimbostratus
Thank you for your post iaine!
Yes I followed the same idea. I query the AD for the user memberOf attribute. Each of the security groups used follows a separate leg of the AD query. Then an iRule assigns pools due to the access policy call. The pool name corresponds with the AD username and now this works fine.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com