VIP RADIUS authentication failure due to missing F5_LTM_User_Info attribute in BIG-IP Access Policy Manager integration
search cancel

VIP RADIUS authentication failure due to missing F5_LTM_User_Info attribute in BIG-IP Access Policy Manager integration

book

Article ID: 450535

calendar_today

Updated On:

Products

VIP Service

Issue/Introduction

During VIP Integration, authentication fails because the BIG-IP Access Policy Manager requires the Remote Role Groups to have the F5_LTM_User_Info string attribute to define user rights. How do we retrieve this F5_LTM_User_Info attribute string from the VIP Validation Server?

Environment

VIP Service

Resolution

The following steps can be used as a reference to retrieve this attribute in the RADIUS response:

  1. Add the user to the f5read or f5write custom group.

  2. Configure the LDAP to RADIUS Mapping (the user filter can be fine-tuned if necessary).



  3. Below is a sample RADIUS response containing the F5_LTM_User_Info_1 attribute.



  4. Restart the validation server.