For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Carlos_13563's avatar
Mar 12, 2014

SSL-VPN Access Policy Client Side Checks

How can I check a client to see if is part of a Windows domain? There are several options I'm just looking for the easiest, would it be by "Registry check", "Windows File Check", "Windows Info", or "Windows Group Policy"?

 

1 Reply

  • gbbaus_104974's avatar
    gbbaus_104974
    Historic F5 Account

    I would use the 'Windows Info' or 'Windows Group Policy' options.

     

    For a more secure/trusted method, you can deploy Machine Certs to all domain connected machines, and then check for the Machine Cert.

     

    You can also parse the 'Windows info' section (any APM session variable that is populated that you like) and do a LDAP check to see if it matches the info on your AD server.