Forum Discussion
Sab
Nimbostratus
Nov 17, 2015How to set different inactivity and Max session timeouts for the users in the different AD group
Hi friends ,
I am new to f5 Apms -irules in particular , I would like some hands on my scenario . We have got multiple clients whose session MAX & Inactivity timeouts needs to be different from one ...
Sab
Nimbostratus
Nov 17, 2015Thanks for the quick reply , let me try this and come back ,.... if i have multiple AD-group/clients which needs different timeout settings , then the irule will look like this:-
when ACCESS_POLICY_AGENT_EVENT {
if { [ACCESS::policy agent_id1] eq "set_timeout_values" } {
switch -glob [ACCESS::session data get "session.ad.last.attr.memberof"] {
"*CN=Standard_SSL_Users*" {
ACCESS::session data set session.inactivity_timeout 150
ACCESS::session data set session.max_session_timeout 200
log local0.notice "Inactivity and Max timeout set"
}
if { [ACCESS::policy agent_id2] eq "set_timeout_values" } {
switch -glob [ACCESS::session data get "session.ad.last.attr.memberof"] {
"*CN= SSL_Users2*" {
ACCESS::session data set session.inactivity_timeout 600
ACCESS::session data set session.max_session_timeout 200
log local0.notice "Inactivity and Max timeout set"
}
if { [ACCESS::policy agent_id3] eq "set_timeout_values" } {
switch -glob [ACCESS::session data get "session.ad.last.attr.memberof"] {
"*CN= SSL_Users3*" {
ACCESS::session data set session.inactivity_timeout 600
ACCESS::session data set session.max_session_timeout 200
log local0.notice "Inactivity and Max timeout set"
}
} } } } } } }
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
