Forum Discussion

Koni_51721's avatar
Dec 02, 2012

Static User to IP mapping for network access on APM

We are planning to migrate from firepass to Big IP APM. At the moment, we use the internal DB for user administration. With APM we want to use a external directory.

 

But is it possible to map an external user (from LDAP-Dir) to a spezific IP address from a defined pool for the network access?

 

If it is possible, we want to administrate the assigned IP also in the directory. How to do that?

 

4 Replies

  • Hi Koni,

     

     

    I don't know why you couldn't try to accomplish this with an iRule. I would think if you get the value from the directory you could then use an iRule to assign it. You could also do a check that says if you don't have a value set then use the default pool. I'm not the best with iRules being a Firepass guy turning APM guy but somebody out here might be able to help with an iRule and tell us if it is possible.

     

     

    Seth
  • Hi Seth

     

    Thanks, it helps. I've tried some configurations and I think there are many ways to solve this problem.

     

  • We assign the IPs from the ldap-directory (ldap-attribut) via access policy.