Forum Discussion
Logging frontended LDAP with SNAT
Our organization frontends LDAP/LDAPS using F5 virtual servers with our DC's as nodes. We have implemented SNAT to resolve asymmetric routing to our DC's. We use an iRule to forward connection details for these VS's using HSL to a SIEM/syslog appliance. The current iRule solves a classic problem created by the SNAT--that of logging source IP addresses, which would be otherwise lost if we weren't logging from F5. Enough background--here's my question:
Has anyone been able to grab other details about the LDAP authentication session such as the user account? Is there a native way to extract this data through an iRule, or some other means such as reading the packet information?
Thanks.
- krisdames_52343Nimbostratus
I too am looking for a solution for this same issue. I have recently become aware of the ASN1 set of commands and I believe they are the answer. Please let me know if anyone has solved this. I'll post my solution if/when I finish it.
https://devcentral.f5.com/wiki/iRules.ASN1.ashx
https://devcentral.f5.com/articles/ber-and-der-why-encoding-and-decoding-matter
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com