Forum Discussion
Nova_201357
Mar 28, 2016Nimbostratus
APM Dynamic ACL assignment from AD
Greetings!
I had a static ACL applied to a Network Access Resource. In testing static assignment, it worked fine. So I took the same logic and formatted as a F5 ACL, put it in AD, in the test acc...
Nova_201357
Mar 28, 2016Nimbostratus
Hey there,
So for anyone who tried this, Brad is right. The ACL must be a single string with all the ACEs concatenated together. In my case, I had to clear out the AD attribute and paste the properly formatted ACL for it to work.
Thanks for the tips Brad!
BTW, F5 should consider documenting things like that!
Cheers, Mike
- Lucas_Thompson_Mar 28, 2016Historic F5 AccountWhere do you think the best place would be to document it? This question comes up sometimes when people put characters like CRLF, or other things that don't translate well to session variables which are plain one-line ascii. In that case, it's auto-transformed to hex encoding.
- Walter_Kacynsk1Mar 29, 2016NimbostratusI would settle on the fact to document how Dynamic ACLs should be represented in AD/LDAP within the product documentation. Information on these are scarce to say the least. However their power is great in that group management is already externalized, so it would make sense to pair the ACLs with the group assignments.
- Nova_201357Mar 30, 2016NimbostratusI'd update this: https://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-implementations-11-5-0/2.htmlconceptid Just add a caveat or a link to a sol doc that goes into greater detail. Thanks, Mike
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects