Forum Discussion
Jo_31162
Nimbostratus
Jul 31, 2013Users logging
Hi,
Is it possible to view (and log) with iRule a username of the clients that access an applicatrion server through the VIP on the BigIP with LTM module only?
Thank in advance
Brgds
4 Replies
- nitass
Employee
how can we get a username e.g. what authentication method is application using? - Jo_31162
Nimbostratus
Hi nitass,
authenticationis performed via LDAP, standard 636 TCP port.Traffic flow is internal, client-to-VIP-to-server.
Tks
- nitass
Employee
sorry i still do not understand.
just a quick question. if you run tcpdump/ssldump on bigip when user do authentication, will you see a username? - Kevin_Stewart
Employee
The bigger question perhaps is if LDAP is traversing the VIP? You also said port 636, so assuming LDAPS? Is it an LDAP client passing through a port 636 VIP, or is this another protocol entirely and LDAP(S) used in another way?
Just for semantics though, if this is an LDAP(S) VIP, and you're decrypting (and potentially re-encrypting) the SSL layer, then it would be possible to grab the BIND message in the LDAP stream. It's not intuitive, but it is possible.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects