Forum Discussion
Checking group when doing APM for activesync
Hello Experts,
I am trying to deploy APM for exchange 2007 with F5 version 11.2.1. I can use a template to build the configuration. However APM is needed as we need to check which group does user belong to, before passing on the traffic.
If I build a normal APM policy with login page and stuff, and I add an LDAP query for the AD group, I can achieve the purpose. But how can I do it in activesync, outookanywhere etc. where there is no login. The irule -sys_APM_activesync is used but I dont't know how exactly is it used ? Does it use the same APM policy as used by OWA traffic but then how does it by pass login page ? If I put ldap query in that policy will it act in same way for active sync traffic as well ?
Any kind of help is much appreciated.
7 Replies
- AndOs
Cirrostratus
Hi!
- SteveVernau_132
Nimbostratus
Hi Andreas what is the Logon user pass box? I need to do this and I dont want the APM policy to force the activesync client to try and hiot a login web page so what is that firsrt box on your VPE that captured the cvreds from activesync auth? - AndOs
Cirrostratus
Hi! The box "Logon User pass" is a standard logon page with "Split domain from full Username" set to yes. Our config was made on 11.2.1 with the iApp that was current back then in 2013 which used the irule _sys_APM_activesync to capture credentials. From there we added on extra queries to check if a user was allowed Active Sync. As far as I know _sys_APM_activesync made sure that active sync clients got handled separatly and didn't "stop" on the logon page. We are still on 11.2.1 for our active sync setup. If you are using a fairly new version, I would suggest looking into the microsoft exchange profile which is available under Access Policy / Application Access. To my knowledge that profile adds the same functionality as irule _sys_APM_activesync. /Andreas
- Pratik_125797
Nimbostratus
Hi Andreas, - AndOs
Cirrostratus
I've only worked with Exchange 2010, so I don't know if there's anything specific that needs to be changed for 2007.
- Pratik_125797
Nimbostratus
Yes, it seems to be generic and even I can see a successful APM session from active sync device but after that I receive a TCP reset from the server and it says unauthorized user. However there is not issue with user credentials. ever got any further with this?
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com