I just tested this in 11.5 and didn't see anything specifically wrong with it. It may be worthwhile to test this from the command line on the F5 using the ldapsearch command:
Query the user:
ldapsearch -H ldap://x.x.x.x:389 -x -b ou=Identities,o=MyCompany -D administrator@mycompany.com -w 'password' '(usershortname=bill.user)'
Query the group membership info:
ldapsearch -H ldap://x.x.x.x:389 -x -b ou=Systems,o= MyCompany -D administrator@mycompany.com -w 'password' '(&(objectClass=groupOfNames)(member=cn=myusercn,ou=People,ou=Identities,o=MyCompany))'