Re: AD Auth for standalone ISA in DMZ



On Jun 25, 5:19 pm, doug.mast...@xxxxxxxxx wrote:
Standalone ISA 2006, single nic, in a DMZ. I need to configure ISA
to poll AD to see if a user is allowed access to the internet or
not. The network boys tell me that they have port 389 open between
my ISA server and my DC's.

The information I'm finding is about using LDAP to authenticate
incoming traffic, and I want to authenticate outbound traffic.



OK, I didn't provide much info, so let me add more about what's been
done and what's been tested.

1. The Network boys finally got 389 open, previously I could not
telnet on port 389 to the DC's and now I can.

2. System Policy #1 (Authentication Services) has been enabled. I
created a Computer Set for the DC's and applied them to the
destination of the System Policy.

3. Under Specify RADIUS and LDAP Servers, I created an LDAP Server
Set with the two DC's, the FQDN is entered, the Use Global Catalog box
is checked, and a valid username & password are entered. The
login Expression to <domain>\* and LDAP Server Set is set.

4. When I try to create a new User Set, I choose the LDAP Server Set
I created and enter the group name of the AD Group that is allowed
internet access. After clicking OK I get a username/password prompt,
after entering that I get the error "None of the configured LDAP
servers are available for verifying the user."


What, if anything, am I missing?

.



Relevant Pages

  • Re: USE of ADFS
    ... but have users in y domain, you cannot authenticate users from y domain ... unless you specify that domains ldap server. ... All domains in the forest trust each other. ... I don't know if ADFS would really help you here or not. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Using LDAP Authentication
    ... If what you need is for you ldap server to authenticate into active directory, ... If what you want is for an authenticated session of your win2k professional ...
    (Focus-Microsoft)
  • Re: Directory Server LDAP/LDIF import - working yet not working???
    ... > authenticate the users, pam_unix retrieves the crypted password and ... we are keeping root and other system-level ... I gave idsconfig all of the information for a proxyagent ... ldap_simple_bind_s: Can't contact LDAP server ...
    (comp.unix.solaris)
  • Re: Authenticating to Kerberos
    ... > Are there any modules that I could use to authenticate against Kerberos ... an LDAP server checks the same "password" as the Kerberos Domain ... Controller (e.g. MS AD or heimdal KDC with OpenLDAP backend). ...
    (comp.lang.python)
  • Re: AD in Remote site not responding when VPN tunnel is down
    ... with also a Cisco ASA to internet. ... All servers have the TCP/IP DNS settings pointing to rAD01 as primary ... Is netmask ordering in DNS turned on, or do you have site definitions so that clients will know how to choose the "local" DCs in favor of DCs that might be at the top of the list? ... If the chosen LDAP server became unavailable, the application would be useless, until the app was restarted or the LDAP server became available again. ...
    (microsoft.public.windows.server.active_directory)