Forum Discussion
Sab
Nimbostratus
Nov 17, 2015How to set different inactivity and Max session timeouts for the users in the different AD group
Hi friends ,
I am new to f5 Apms -irules in particular , I would like some hands on my scenario . We have got multiple clients whose session MAX & Inactivity timeouts needs to be different from one ...
Michael_Jenkins
Cirrostratus
Nov 17, 2015You would do something like this, just adding other criteria to the switch statement.
when ACCESS_POLICY_AGENT_EVENT {
check for policy agent_id
if { [ACCESS::policy agent_id] eq "set_timeout_values" } {
switch -glob [ACCESS::session data get "session.ad.last.attr.memberof"] {
"*CN=Standard_SSL_Users*" {
ACCESS::session data set session.inactivity_timeout 150
ACCESS::session data set session.max_session_timeout 200
log local0.notice "Inactivity and Max timeout set (1)"
}
"*CN=SSL_Users_2*" {
ACCESS::session data set session.inactivity_timeout 200
ACCESS::session data set session.max_session_timeout 300
log local0.notice "Inactivity and Max timeout set (2)"
}
"*CN=SSL_Users_3*" {
ACCESS::session data set session.inactivity_timeout 300
ACCESS::session data set session.max_session_timeout 400
log local0.notice "Inactivity and Max timeout set (3)"
}
}
}
}
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
