Forum Discussion

Maynor_Ovalle's avatar
Maynor_Ovalle
Icon for Nimbostratus rankNimbostratus
Nov 07, 2013

How to configure APM to use AD Global Catalog 3268 and or 3269? Does APM support Authentication using Global Catalog?

I'm using APM and there is a requirement to authenticate users through Global Cagalog instead of regular AD Kerberos or LDAP 389 636. We would like to use the AD Global Catalog which are basically 3268 and 3269 but can't seem to get this to work.

 

3 Replies

  • Got an aswer from F5. As of 11.4.1 Global Catalog is not supported yet for authentication. Supported are ldap, ldaps, regular AD and Kerberos.

     

    • dirtycache's avatar
      dirtycache
      Icon for Nimbostratus rankNimbostratus

      Circling back to this as the post/question came up in a Google search -

       

      You can utilize the global catalog by configuring it as an LDAP AAA server object, with the dependent pool members using port 3268/tcp.

       

      That said, you won't have password change functionality with an LDAP AAA object like you would with AD due to them each using a different agent; the LDAP agent does not support this feature while the AD agent does, including against RODCs.