Forum Discussion

Cay_Jeglinski_1's avatar
Cay_Jeglinski_1
Icon for Nimbostratus rankNimbostratus
Mar 13, 2015

APM - How to assign user specific lease pool to network access policy?

We need to implement our vpn policy on APM network access policy.

 

Our security policy states, each individual person needs to be assigned with an individual user account and an individual ip address. As far as I understand the APM network this results in individual pool configuration along with individual profiles.

 

Would anyone have faced this requirement too? Would there be a dynamic assignment with say radius authorization or user mapping to reduce the amount of profiles in APM?

 

Any suggestions welcome!

 

2 Replies

  • Are you able to query AD...? If so, you could store the IP address in the user object as a custom attribute. Then, as part of the login sequence, query AD to extract the IP and then use that as the client IP

     

  • Thank you for your post iaine!

     

    Yes I followed the same idea. I query the AD for the user memberOf attribute. Each of the security groups used follows a separate leg of the AD query. Then an iRule assigns pools due to the access policy call. The pool name corresponds with the AD username and now this works fine.