Forum Discussion
Cannot get domain in iRule after APM logon page
Hi all.
I'm trying to get the domain forest out of the user logon. I enabled 'split domain' on the APM logon page, added a None-type domain field with domain session variable but
session.logon.last.domain keeps returning nothing.
Point is currently we only match the username as you can see. But we don't xx-D/user to authenticate in favour of AVI-DC/user. We only configured one AD server, but I believe this one will forward the authentication to others.
Any suggestions?
(as always, irule pasting here is horrible.) irule: http://pastie.org/private/poewrrnepgbylxih7wyvsw
Don't really get the iRule used here.
If you enable split domain, basically the logon agent will break the logon.last.logonname to logon.last.username and logon.last.domain. So user might enter the logonname like
oruser@mydomain.locmydomain.loc\user
8 Replies
- kunjan_118660
Cumulonimbus
Don't really get the iRule used here.
If you enable split domain, basically the logon agent will break the logon.last.logonname to logon.last.username and logon.last.domain. So user might enter the logonname like
oruser@mydomain.locmydomain.loc\user- NiHo_202842
Cirrostratus
The irule is used to check the username against a data group for whitelisting purposes on top of AD authentication that is done by APM. Logging shows that logon.last.domain is empty.
- kunjan
Nimbostratus
Don't really get the iRule used here.
If you enable split domain, basically the logon agent will break the logon.last.logonname to logon.last.username and logon.last.domain. So user might enter the logonname like
oruser@mydomain.locmydomain.loc\user- NiHo_202842
Cirrostratus
The irule is used to check the username against a data group for whitelisting purposes on top of AD authentication that is done by APM. Logging shows that logon.last.domain is empty.
- kunjan_118660
Cumulonimbus
1) How the logonname is entered, the format ?
2) Can you do a sessiondump to verify?
3) which version are you having ? Tested working in 11.6- NiHo_202842
Cirrostratus
It seems it does work if we explicitly ask domain\ in the username. Thanks for the effort tough!
- kunjan
Nimbostratus
1) How the logonname is entered, the format ?
2) Can you do a sessiondump to verify?
3) which version are you having ? Tested working in 11.6- NiHo_202842
Cirrostratus
It seems it does work if we explicitly ask domain\ in the username. Thanks for the effort tough!
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
