Forum Discussion
Jason_Jernigan1
Nimbostratus
Jan 10, 2007Possible to query LDAP from an Irule?
I'm trying to figure out if it is possible to query LDAP for an attribute of a user then make a decision on the pool based on that attribute? If I could run a bash script or command and return a value from an irule this would also be possible since ldapsearch is on the bigip. Any help in pointing me in the right direction is greatly appreciated.
Thanks,
Jason
- Don_MacVittie_1Historic F5 AccountHey Jason,
- Jason_Jernigan1
Nimbostratus
This is one of the concerns I thought of. However would it be possible to persist the attribute so that it only does the LDAP query for a new session? I think we could take the latency hit on the initial connection, our use case is that once users are logged in they stay logged in for long periods of time and we don't have huge numbers of users logging in. We are already doing LDAP authentication at the bigip. I'd like to give this a shot. If you can point me in the right direction that would be greatly appreciated. - Don_MacVittie_1Historic F5 AccountHey Again Jason,
- Jason_Jernigan1
Nimbostratus
Ok so it looks like to try this out I will have to upgrade to 9.2. This isn't a problem will probably take me a day or two to get it done. Feel free to contact me via email to discuss next steps. - Jason_Jernigan1
Nimbostratus
I was looking for answers to another problem I have when I came accross a command that I think could be used to solve my problem. I would like to get your inputs on this. The command is AUTH::response_data it is only available in 9.4.0. The wiki entry is here http://devcentral.f5.com/wiki/default.aspx/iRules/AUTH__response_data.html - david_wang_2073Historic F5 AccountHi, Jason,
- hoolio
Cirrostratus
Has any progress on making an LDAP query from an iRule been made in recent versions? If so, can you provide details? I have a customer who is interested in load balancing HTTP traffic by selecting the pool based on LDAP query results. The search base and filters could potentially need to be changed per URI. - Ping_Xiong_1567Historic F5 AccountAny update about this thread? I'm coming cross the same requirement, need to query attribute from LDAP for a SLB decision.
- hoolio
Cirrostratus
The simplest option for this now is to use APM (Access Policy Manager) to query LDAP and make load balancing decisions based on the returned attributes. - gpoverland
Nimbostratus
Hoolio,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects