USG FLEX 200H (uOS 1.39, Nebula-managed): AD bind account works only in CN=Users — "Invalid DN synta
Freshman Member
Nebula-managed USG FLEX 200H, uOS 1.39, NCC 20.10, Windows Server 2022 AD. The AD server object (NCC → Firewall settings → Authentication Server) authenticates SSL-VPN users.
With the bind account in its own OU (a dedicated service account, Domain Users only), the Configuration Validation test returns "Invalid DN syntax" for every user. Moving the same account to CN=Users makes the test pass and SSL-VPN logins work. The uOS 1.35 release notes added a Bind DN Base field in the local GUI for exactly this, but NCC's AD server Advanced dialog does not expose it, so any value set locally is overwritten by the next NCC push.
Two questions: Is CN=Users currently the only supported location for the bind account on Nebula-managed H-series firewalls? Is Bind DN Base planned for NCC?
All Replies
-
Hi @ChipW,
1.Is CN=Users currently the only supported location for the bind account on Nebula-managed H-series firewalls?
Yes. If the 'Bind DN Base' field is left unconfigured, the firewall defaults to assuming the bind account resides in the 'CN=Users' container. At present, NCC does not provide an option to configure the 'Bind DN Base' field.
Starting from uOS 1.35, the "Bind DN Base" field in the local Web GUI allows you to specify the OU where the bind account is located, and this configuration will be applied to the device.
However, modifying the AD server settings in NCC should not overwrite the "Bind DN Base" value configured in the local Web GUI(as shown in the screenshot).
If you notice that changing settings in NCC directly overwrites the 'Bind DN Base' value in the local Web GUI, or if AD authentication unexpectedly fails and you suspect the on-device configuration has been overwritten, please provide relevant screenshots. We will look into this further to clarify the behavior.
Additionally, if possible, please follow the FAQ below to enable Zyxel Support Access and share your Organization and Site names with us so we can better assist you:
[Nebula] How to turn on Zyxel Support Access? — Zyxel Community
2.Is Bind DN Base planned for NCC?
It is not available at the moment. Thank you for sharing your feedback with us. We have forwarded your request for future evaluation. You can track and contribute to this idea in the following section:
Add "Bind DN Base" to the AD Server settings in NCC for USG FLEX H Series
Thank you for using Zyxel products and services.
0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 241 Nebula Ideas
- 6.8K Security
- 755 USG FLEX H Series
- 380 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.5K Wireless
- 58 Wireless Ideas
- 7.2K Consumer Product
- 321 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.3K FAQ
- 34 Documents
- 90 About Community
- 119 Security Highlight
Zyxel Employee
