There's a mobile version of our website.
I'm searching for a solution to web authenticate users within a specific Active Directory Security Group. I tried to authenticate over Radius with Cisco Secure ACS and Network Access Restrictions. But NAR only works with Layer 2 authentication. And Web Authentication over LDAP can only be used with User Objects.
Are you trying to authenticate Administers of the WLC's to AD or are you trying to use WebAuthentication allowing access to the Security Group? If you are trying to use ACS to allow for Administers to have access to the WLC's then you would use ACS TACACS not radius. You would need role1=ALL as a shell profile for that policy and point to your Security Group in AD.
Do a search for role1=ALL on this forum and you will get many hits.
That is the same with IAS/NPS also, you have to point to an OU. I was thinking you specified a Security Group OU. The only workaround is to put the Security Group users in a new OU that radius can be pointed to.
Sent from my iPhone
You and maldehne are saying the correct thing. However, this is some kind of limitation that cisco should improve in the future. classifying users based on groups in AD is more flexible than classifying based on OU's when using LDAP. If there is anything that can be implemented to classify users based on AD groups at Layer 3 auth level that will be very useful functionality for cisco products.
Have those users only under certain container on your LDAP server and use its DN as the user Base DN to be defined on the controller , thus restricting the search for that branch of the LDAP Tree.
Login to share your discussion activity with your friends on Facebook. You can control what you share and turn off sharing anytime.
Your Facebook friends can now see that you have started this discussion
Your Facebook friends can now see that you have commented on this discussion
Your Facebook friends can now see that you have read this discussion