Forum Discussion
Mike_Finney_119
Nimbostratus
Sep 09, 2013LDAP query for machine account?
I am still trying to flesh out our VPN solution but I am running into some issues with the client validation checks to fulfill security requirements. I would like to check to see if the remote client...
Mike_61719
Cirrus
Sep 13, 2013Mike, you might want to consider multiple verification processes in place to determine access and not rely upon a domain name ldap check. That isn't exactly the safest method ;)
In addition, I'm not sure if you're using the edge gateway or not but the i-rule isn't necessary. There are built in checks to make this work.
Mike_Finney_119
Nimbostratus
Sep 16, 2013Hi Mike,
Thanks for the reply. Not sure which built in checks you are referring to there, but we are on APM 11.4. I am doing several checks to try to validate the machine as being part of our domain, this is what I have currently.
1. pull the machine name as above, then do an LDAP query against the domain to see if the computer account is a member
2. do a client side registry check for this key: ""HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internaldomain.lan" as it will only be populated after a successful GPO push with our domain policy that includes the IE trusted zones.
3. Finally, I do a process check for our client inventory/asset management software. If it is installed, then they can pass.
I know it isn't perfect but I believe it is very very unlikely someone could fake all three simultaneously, and would require more effort than it would be worth.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
