Manual Chapter : Creating an LDAP Authentication

Applies To:

  • BIG-IP APM

    21.0.0, 17.5.1, 17.5.0, 17.1.3, 17.1.2, 17.1.1, 17.1.0, 17.0.0, 16.1.6, 16.1.5, 16.1.4, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0

Creating an LDAP Authentication

You create an LDAP Authentication when authentication or authorization data is stored on a remote LDAP server or a Microsoft Windows Active Directory server. You can configure it for LDAP or LDAPS.

  1. On the Main tab, click Access > Authentication > LDAP.

  2. Click Create.

  3. For Name, type a name for the LDAP Authentication Configuration.

  4. For Server Connection, leave the default Use Pool. selected.

  5. For Server Pool Name, type a name for the server pool.

  6. For Server Addresses, type the IP addresses of each server pool member and click Add.

    Set the priority for each pool member by using the Up andDown buttons.

  7. Configure LDAP or LDAPS:

    • For LDAP: Leave Mode set to LDAP, and Service Port set to 389.
    • For LDAPS: Set Mode to LDAPS, and Service Port set to 636.
  8. For Base Search DN, type the base distinguished name from which to search.

  9. For Admin DN, type the distinguished name (DN) of the user with administrator rights.

  10. For Admin Password, type the admin password for the LDAP server.

  11. For Verify Admin Password, verify the password again.

  12. For Group Cache Lifetime, specify the lifetime (in days) of a group cache. The default lifetime is 30 days.

  13. If using LDAPS, for SSL Profile (Server), select the profile such as apm-default-serverssl.

  14. Click Finished.

The LDAP Authentication is created.