Forum Discussion
Device posture check without F5 Access guard
Hi shashe - some solid questions. I got rid of the spammer who replied to your post. I think James_Jinwon_Lee could answer your questions if nobody else chimes in.
- James_Jinwon_LeeSep 28, 2022Employee
shashe APM also can collect limited device information from HTTP headers without additional S/W installation. However, if you need to collect detailed device information from the client, SW installation is required.
- shasheSep 28, 2022Cirrus
James_Jinwon_Lee Thanks for your response. can you please detail the information it collects? What device posture checks can I enforce without the need for additional s/w clients. We have a combination of MAC,windows, android and iphones.
Thanks.
- James_Jinwon_LeeOct 01, 2022Employee
shashe F5 APM supports two types of endpoint posture checks as a policy in the VPE(Visual Policy Editor), 'Client-Side' and 'Server-Side'. For the 'Client-Side' check, we need to install 'Endpoint Inspection' S/W to check the specific information from the client machine. So, in this method, APM can do detail checking such as file existence, AV status, Windows registry and etc. However, for the 'Server-Side' check, we use the header and other network telemetry data we can collect from the request. Thus, the information we can check in this method is quite limited, such as IP geolocation, IP reputation, client OS, browser type and etc.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com