Forum Discussion
Securing OWA using APM from Outside for specific users
Hi,
We have deployed our 2013 exchange environment using the iApps template. Initially, we did not opt to use APM but we are circling back around with unique requirements.
We have two requirements:
-
Secure OWA based on specific security groups. I believe I can achieve this by modifying the access profile using the AD Group Resource Assign container.
-
Secure OWA based on specific security groups only allowing inside access. Basically, we want to give OWA to internal teams and restrict this OWA access from outside the company. My thought is, we would need an iRule or something to identify that a public IP + a security group was attempting access and deny the resource.
Looking for feedback on my ideas and thought process.
2 Replies
- Lucas_Thompson_Historic F5 Account
No irules necessary, you can build both pieces of logic inside of your Access Policy. For groups, you can just use "AD Query" or "LDAP Query" and success branch from that if the group name appears in the response. For IP address checking, you can use a similar technique to branch from a result by checking the client IP session variable.
- Nfordhk_66801
Nimbostratus
Perfect! I didn't know subnet match was an option. I was able to use AD query and match based on group membership. Thanks for your help!
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com