05-04-2012 07:27 AM - edited 07-03-2021 10:06 PM
Hey
I'm searching for a solution to web authenticate users within a specific Active Directory Security Group. I tried to authenticate over Radius with Cisco Secure ACS and Network Access Restrictions. But NAR only works with Layer 2 authentication. And Web Authentication over LDAP can only be used with User Objects.
Any ideas?
best regards,
Marc
Solved! Go to Solution.
05-12-2012 10:33 PM
Scott:
You and maldehne are saying the correct thing. However, this is some kind of limitation that cisco should improve in the future. classifying users based on groups in AD is more flexible than classifying based on OU's when using LDAP. If there is anything that can be implemented to classify users based on AD groups at Layer 3 auth level that will be very useful functionality for cisco products.
05-05-2012 08:22 AM
Are you trying to authenticate Administers of the WLC's to AD or are you trying to use WebAuthentication allowing access to the Security Group? If you are trying to use ACS to allow for Administers to have access to the WLC's then you would use ACS TACACS not radius. You would need role1=ALL as a shell profile for that policy and point to your Security Group in AD.
Do a search for role1=ALL on this forum and you will get many hits.
05-05-2012 09:28 AM
No, i want to control access over web authentication with AD Security Groups. With web authentication over LDAP, I cannot define security groups, only OU's.
05-05-2012 09:35 AM
That is the same with IAS/NPS also, you have to point to an OU. I was thinking you specified a Security Group OU. The only workaround is to put the Security Group users in a new OU that radius can be pointed to.
Thanks,
Scott Fella
Sent from my iPhone
05-12-2012 10:33 PM
Scott:
You and maldehne are saying the correct thing. However, this is some kind of limitation that cisco should improve in the future. classifying users based on groups in AD is more flexible than classifying based on OU's when using LDAP. If there is anything that can be implemented to classify users based on AD groups at Layer 3 auth level that will be very useful functionality for cisco products.
05-12-2012 08:36 PM
Have those users only under certain container on your LDAP server and use its DN as the user Base DN to be defined on the controller , thus restricting the search for that branch of the LDAP Tree.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: