USG310: AD Users can't connect IKEv2 since update 4.35 AAPJ0

Options
KMB
KMB Posts: 2  Freshman Member
Second Anniversary
edited April 2021 in Security

since updating to firmware 4.35 AAPJ0 AD-users get an "Auth fail", while connecting via IKEv2. Local Users are no problem.

I have checked "AAA-Server" settings and the test function for username still delivers "ok". Auth method is first still "group ad" an second is local.

In IKE log only "auth fail" is diplayed..


Can anyone help?

All Replies

  • Zyxel_Emily
    Zyxel_Emily Posts: 1,427  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

    Hi @KMB,

    The USG310 must join an AD domain.

    In the following example, domain name is usg.com.

    Go to CONFIGURATION > System > Host Name and enter the domain name.

    image.png

    Go to CONFIGURATION > System > DNS > Address/PTR Record and add a record for AD server.

    image.png

    On AD server, usg310 should appear in Computers.

    image.png

    Go to AAA Server > Active Directory > AD object. Configure Domain Authentication for MSChap.

    The user in this field should belongs to “domain admin” on your AD server.

    image.png

    Result: IKEv2 is established with AD account successfully.

    image.png image.png