Forum Discussion

Peter_Kim's avatar
Peter_Kim
Icon for Nimbostratus rankNimbostratus
Nov 13, 2019

BIG-IP APM Edge Client for Mac

I'm fairly new to BIG-IP APM Edge Client. We currently have Edge client setup for Windows client. However, I'm trying to add a Mac. My question, is there anything I can setup to check if Mac is company issued Mac before they can even start the VPN session? I understand that we can use Windows Registry for Windows client to check if it is on our corporate domain or not. I'm looking for something similar feature for Mac. Only options I see are "Mac Process and Mac File". Are these something I can use to check the Mac for their identities? I would appreciate any suggestions.

Thanks.

3 Replies

  • Running dsconfigad -show

    should output something.

    But I don't think APM can directly gather this and check this.

    Other than what you mentioned, the common method is usiing machine cert auth

    • Peter_Kim's avatar
      Peter_Kim
      Icon for Nimbostratus rankNimbostratus

      Thanks for your replay. By any chance, is there a good document how to use "machine cert auth" for Mac client?

  • There are.

    https://techdocs.f5.com/kb/en-us/products/big-ip_apm/manuals/product/big-ip-access-policy-manager-visual-policy-editor-14-1-0/03.html#guid-bb209ab6-68ab-4bf0-9c82-ac5e767f5816

    The "About Machine Cert Auth" section

    https://support.f5.com/csp/article/K15302653#link_02_07

    https://support.f5.com/csp/article/K13614

     

    Hope it all works out..