Forum Discussion
Mike_Finney_119
Nimbostratus
Sep 09, 2013LDAP query for machine account?
I am still trying to flesh out our VPN solution but I am running into some issues with the client validation checks to fulfill security requirements. I would like to check to see if the remote client...
Mike_61719
Cirrus
Sep 13, 2013Mike, you might want to consider multiple verification processes in place to determine access and not rely upon a domain name ldap check. That isn't exactly the safest method ;)
In addition, I'm not sure if you're using the edge gateway or not but the i-rule isn't necessary. There are built in checks to make this work.
Mike_Finney_119
Nimbostratus
Sep 16, 2013Hi Mike,
Thanks for the reply. Not sure which built in checks you are referring to there, but we are on APM 11.4. I am doing several checks to try to validate the machine as being part of our domain, this is what I have currently.
1. pull the machine name as above, then do an LDAP query against the domain to see if the computer account is a member
2. do a client side registry check for this key: ""HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\internaldomain.lan" as it will only be populated after a successful GPO push with our domain policy that includes the IE trusted zones.
3. Finally, I do a process check for our client inventory/asset management software. If it is installed, then they can pass.
I know it isn't perfect but I believe it is very very unlikely someone could fake all three simultaneously, and would require more effort than it would be worth.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects