NAC authentication via Windows AD
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-20-2011 12:55 AM - edited 02-21-2020 10:25 AM
Hi,
we have a Nac enviroment with users that are defined on the ACS. Also the groups are defined on this machine.
The problem is that we have to move all the users from the ACS to the domain controller, so all the users will become AD users.
In which way we have to configure the NAC enviroment to permit the authentication via Active Directory instead of Radius that runs on the ACS?
Thanks a lot!
Leonardo
- Labels:
-
Other NAC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2011 05:27 AM
Hi Leonardo,
If the users log in in windows domain, so do you configure Single Sign On
else, you can configure by LDAP.
See the images...
I'm Brazilian, if you want more informations, contact me
Daniel Stefani
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2011 05:42 AM
Great Daniel,
I've already configured a radius server on the "Auth Servers"...can you confirm me that adding a new "LDAP" server will not influence or cause interruption of service for the roles that are already defined?
If I've understood well the "Server mapping" must be done when we create the role...or not?
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2011 06:03 AM
Hi Leonardo,
Not cause any interruption.
In my environment is configured LDAP Auth Server and did not need to map because I'm using just a Role, so this is configured as Default Role in Auth Server settings
Tks
Daniel Stefani
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2011 06:05 AM
So, If It is so...only if you add more than one auth server you chan choose the mapping?
I'm migrating the user from radius (ACS) to LDAP (AD)...so I have a mixed enviroment for some time!!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2011 06:20 AM
You have to create a map rule if you have two or
more Roles authenticating in the same LDAP Auth Server
and not if you have two or more auth servers
If the users authenticating today in Radius Server ACS is associated with a single Role XYZ, then you can configure the LDAP Server linking users to the same Role XYZ.
You will have two providers for the same Role.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2011 06:23 AM
Thanks a lot for the answers! :-)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2011 02:31 AM
I have another doubt.
Today with radius in the mapping I have the situation in the screenshot attached.
Which attribute I've to use if I have a mapping rules Vs Ldap (Domain Controller?)
Can you tell me this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2011 06:51 AM
Sorry, but i don't know.
Do you intend mapp by groups in AD ?
If you discover, tell us.
Tks
Daniel Stefani
