Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

How do I search through the active directory forest for radius authentication - I need the users to be able to logon without specifying thier domain

Posted on 2006-10-28
8
Medium Priority
?
206 Views
Last Modified: 2010-03-18
I have been given the task of making our vpn user id's and passwords the same as our Active directory.

Our AD environment consists of one forest and 5 different domains

the user needs to be able to vpn in with  firstname lastname

I thought we could point our vpn device to windows/IAS radius and this would be possible - it is possible, but the user has to specify thier domain name when they log in....

Specifying the domain name is not an option for me - I can only use firstname lastname - I need something that will make radius search through our entire ad structure to find the user name (all our user names are unique)

0
Comment
Question by:scarm
  • 2
  • 2
8 Comments
 
LVL 6

Expert Comment

by:camacho_marco
ID: 17840715
Try and use Cisco VPN concnetrator, it has LDAP and you do not specify a domain only user and password.

Cheers
0
 

Author Comment

by:scarm
ID: 17847509
do you have to use distinguished or fully qualified names?

Also, our vpn is not cisco - it's F5 network's uroam product

- multiple domains - users need to login without specifying domain name
0
 

Author Comment

by:scarm
ID: 17911109
Nobody has any radius / active directory experience out there??
0
 
LVL 9

Accepted Solution

by:
CLoz earned 2000 total points
ID: 18097267
If you are using the F5 Firepass you should be able to create a Master Group that authenticates directly with your AD server.  As long as you don't have users with matching ID's across the 5 domains you will not need to supply the domain name during authentication.  

Let me know if you need help creating the Master Group.

-Cloz
0
 
LVL 6

Expert Comment

by:camacho_marco
ID: 19406994
split points
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Need In an Active Directory enviroment, the PDC emulator provide time synchronization for the domain. This is important since Active Directory uses Kerberos for authentication.  By default, if the time difference between systems is off by more …
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question