Forum Discussion
BP_Soh_11405
Nimbostratus
Dec 02, 2008Restrict user from logging according to group and time
Hi All,
Is it possible to do the following on Firepass?
1. To restrict user from logging if they belong to certain group at certain time.
2. To prompt to user that they are logging in at the wrong time if only protect resource can be configured. (A pop up message)
5 Replies
- psilvas
Altostratus
Hi~
you should be able to do this with the VPE (prelogon editor) and/or Protected Resources/Protected Configurations (Users>Endpoint Security). Create a time Protected Config and attach it to the Resource Group or choose Check Time (preconfig inspector) in Prelogon sequence and name your time. If it's late enough in the check, then you should be able to present a message on the Logon Denied page. Hope that helps.
ps - BP_Soh_11405
Nimbostratus
HI, I only want to restrict a group of user not all. Is there any way? - psilvas
Altostratus
Hi~
Are there any other identifiable checks you could make for those who do not have the time restriction? like client cert or machine cert or RegKey or something like that? For instance, you could do a check for client cert (early in the process) knowing only certain (internal employees) folks would pass - then they get to authenticate and access resources. You could then build a fallback path (for those without certs) which could still check AV/FW, etc, along with the Time restriction. That would allow those without restrictions access and the others would have to abide by the time designation. You could also add time restriction to the resource - meaning you might still 'let them in' but limit what resources they have access to depending on the time.
ps - BP_Soh_11405
Nimbostratus
Hi, no there is no other identifiable checks. I have try protected resources and it show a "blank" page when these users login at specific timing. What i need is an prompt informing that the "blank" page is due to time restriction and not F5 issue. - psilvas
Altostratus
so that's odd since there should be a red 'System Warning' message at the top of their webtop (FP resource landing page) after they authenticate. If they click on the Warning, it should take them to the default message that they have some restrictions & if I remember correctly, it'll tell them it is due to the time setting.
ps
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
