For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Cthulhucalling_'s avatar
Feb 14, 2014

APM not catching MAC address

In APM, I'm trying to do a few client-side checks. One of the things I'm looking at is the MAC address of the client connecting to APM, and trying to deny if it sees that it's a VMware guest connecting. In VPE, I have a Client-side Security check for Machine Info. I have an advanced expression:

expr { [mcget {session.machine_info.last.net_adapter.list.[0].mac_address}] contains "00:0c:29" }

Policy is set to Deny if APM catches this OUI. This doesn't work. Trimming the MAC prefix to just

expr { [mcget {session.machine_info.last.net_adapter.list.[0].mac_address}] contains "00" }

this DOES work, but obviously not going to be workable. I've tried escaping the colons but that doesn't seem to work either. Any suggestions?

1 Reply

  • Figured out out. Despite the MAC address in the APM log being 00:0c:29, it really wants all the letters to be capitalized 00:0C:29