Hello Jason,
This isn't exactly related to iRules, but...
Client LDAP authentication is an add-on feature enabled by license. If you check your license (/config/bigip.license or in the GUI under System >> License) do you see a Client Authentication key, as in the example below?
License Tokens for Module Client Authentication key XXXXXXX-XXXXXXX
security_ssl_client_verify_ocsp : enabled
security_ta_http : enabled
security_ta_ldap : enabled
security_ta_radius : enabled
security_ta_tacacs : enabled
If you want to add a license token for client LDAP authentication you can contact your F5 salesperson for more info.
Aaron