cancel
Showing results for 
Search instead for 
Did you mean: 
Login & Join the DevCentral Connects Group to watch the Recorded LiveStream (May 12) on Basic iControl Security - show notes included.

APM - Allow session by checking if Session Variable exist in a List/DB

Jorjjj
Nimbostratus
Nimbostratus

Hello

I need to Build a use case, where I need to allow only specific Machines to access a web applications.

 

The best approach i reached to was through the APM module, where i can retrieve the Machine info, and validate the BIOS Serial number (which is unique among different machines) against a list of Allowed SN.

 

  • If the variable (

session.machine_info./Common/Test-Access_act_machine_info_ag.bios.sn) exist in list ==> Grant Access to Web app

 

  • If the variable does not existing the list ==> DROP access (And provide a way for the admin to include it to the list if it's an approved machine)

 

If this a good approach to do? or is there any other easier and practical way to authenticate a Machine before granting access?

If yes, where should i write the list of allowed BIOS SN, and how to do make Validation check (If SN exist in LIST)

 

Regards,

Georges.

1 REPLY 1

Dave_W
F5 Employee
F5 Employee

Hello, where is the list of allowed BIOS numbers? In a attribute in say AD? Or in a datagroup within the BigIP?

 

https://techdocs.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-config-11-4-0/apm_config_cl...