Forum Discussion
How to configure APM to use AD Global Catalog 3268 and or 3269? Does APM support Authentication using Global Catalog?
I'm using APM and there is a requirement to authenticate users through Global Cagalog instead of regular AD Kerberos or LDAP 389 636. We would like to use the AD Global Catalog which are basically 3268 and 3269 but can't seem to get this to work.
3 Replies
- Maynor_Ovalle
Nimbostratus
Got an aswer from F5. As of 11.4.1 Global Catalog is not supported yet for authentication. Supported are ldap, ldaps, regular AD and Kerberos.
- dirtycache
Nimbostratus
Circling back to this as the post/question came up in a Google search -
You can utilize the global catalog by configuring it as an LDAP AAA server object, with the dependent pool members using port 3268/tcp.
That said, you won't have password change functionality with an LDAP AAA object like you would with AD due to them each using a different agent; the LDAP agent does not support this feature while the AD agent does, including against RODCs.
- chris_stennie_1
Nimbostratus
Any updates on this? Has it been added to the current version?
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com