cancel
Showing results for 
Search instead for 
Did you mean: 

Looking for a Method to Disconnect Active Session, when LDAP user is Disabled

michael.l.fusco@jpl.nasa.gov
Occasional Contributor

Looking for a Method to Disconnect Active Session, when LDAP user is Disabled

Hello Community,

 

Looking for a way to enforce disconnection of an Active VPN Session when the LDAP user status is changed form "Employed" to "Terminated".

 

Taking all Ideas.

5 REPLIES 5
zanyterp
Moderator

Re: Looking for a Method to Disconnect Active Session, when LDAP user is Disabled

we do not have anything on-appliance that will do that
if you have a script that runs to trigger a series of actions on multiple systems when that happens, you can add the pcs to that mix and terminate any session for the user via REST
michael.l.fusco@jpl.nasa.gov
Occasional Contributor

Re: Looking for a Method to Disconnect Active Session, when LDAP user is Disabled

What about Dynamic Role assingment?
Can the PCS every "15 mins" query the status of a User's Object in LDAP and if an Attrb or membership change move the Active session from a "role-allow" to a "role-quarentined"

 

michael.l.fusco@jpl.nasa.gov
Occasional Contributor

Re: Looking for a Method to Disconnect Active Session, when LDAP user is Disabled

Has Anyone every use the Pulse Secure Profiler PPS to do this?

zanyterp
Moderator

Re: Looking for a Method to Disconnect Active Session, when LDAP user is Disabled

there is currently nothing on the system that will run the query against LDAP after login; those values are set until the end of the session and the user attempts login again
zanyterp
Moderator

Re: Looking for a Method to Disconnect Active Session, when LDAP user is Disabled

i do not believe profiler is able to terminate sessions; however, i would recommend opening a case with our support team to confirm