Transparent AD authentication
All Replies
-
@sk8erbender
Regarding this case,
after users do authentication from Windows logon page, they dont need to be authenticated by USG again.
Can you double check the log message or login user page to confirm user truly login via SSO?(Go to Monitor>System Status>Login Users)
The attached steps of configuration on USG and SSO agent side as your reference.
SSO Agent
Charlie
5 -
Zyxel_Charlie said:@sk8erbender
Regarding this case,
after users do authentication from Windows logon page, they dont need to be authenticated by USG again.
Can you double check the log message or login user page to confirm user truly login via SSO?(Go to Monitor>System Status>Login Users)
The attached steps of configuration on USG and SSO agent side as your reference.
SSO Agent
Charlie
0 -
Go to CONFIGURATION > Object > User/Group > User and add a new
ext-group-user.Ex: csosecurity. The domain user “Amy” must belong to this group in the AD.I didnt add group in usg 310 could it be a problem?Can i add Domain users group ? Or I have to make separate one?Also Force user authentication should I tick this or leave it empty ?
0 -
Also , any ports needed to be opened to communicate form USg ( incoming ) on active directory ?
Ports beside default sso on USg itself ?
Tried every single option - adding group and users , ticking force aouthentication on and off .
I can see logged users in sso app on domain controller and logs shows no errors.0 -
Damn Guys ) I’ll buy 2 beers for those who help me complete setting this up . I’m sure I’m stuck on something stupid ..0
-
Update - well seems to be opening port 2158 on domain controller solved the problem . Now users show up on USg user list I hope I can open port for application only not the just tcp rule ?0
-
Well ( it works for like 15-30 minutes then users get disconnecting from internet asking to enter credentials on USG web page.After they log out , then log in again, it works again for 15-30 minutes or so. How do I diagnose this problem?0
-
@sk8erbender
Regarding to this case,
can I know what issue did you face currently, and more details about"I hope I can open port for application only not the just tcp rule "?
Also, can you double check the log message or login user page to confirm user truly login via SSO?(Go to Monitor>System Status>Login Users)
If there is not User ID on the list, you may double check the configuration on SSO agent and USG.
Charlie0 -
Zyxel_Charlie said:@sk8erbender
Regarding to this case,
can I know what issue did you face currently, and more details about"I hope I can open port for application only not the just tcp rule "?
Also, can you double check the log message or login user page to confirm user truly login via SSO?(Go to Monitor>System Status>Login Users)
If there is not User ID on the list, you may double check the configuration on SSO agent and USG.
Charlie
0 -
@sk8erbender
Regarding to this case,
I will private message to you for more details. Please has a check.
Charlie0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 145 Nebula Ideas
- 95 Nebula Status and Incidents
- 5.6K Security
- 239 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 385 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 72 Security Highlight