Forum Discussion
FritzHege_14885
Nimbostratus
Feb 18, 2016LDAP Group Resource Assign - not working - APM 11.6 HF6
I have a portal access policy that allows the user to authenticate into the portal but when the LDAP Group Resource Assign assigns the Group (LDAP Room 999999) the user receives "denied by access policy". The user is actually in a LDAP room versus a LDAP Group so my syntax may be incorrect.
This is what i have configured to use to try to use LDAP Group/Room: expr { [mcget {session.ldap.last.attr.roomNumber}] contains [mcget {session.aa.room}] }
It may be that LDAP rooms are not the same as LDAP Groups or i believe TAC was telling me to change the expression but not sure how to do that.
Any ideas are greatly appreciated.
1 Reply
- Josiah_39459Historic F5 AccountI would suggest using the sessiondump command or viewing the session report to make sure those variables are being set the way you expect. There is nothing wrong with the TCL expression you have written, so you need to verify those variables contain the values you expect them to.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects