L2TP VPN server - AD authentication
Hi
Trying to set up VPN for clients using my AD server for authentication on a Flex200.
Everything works, but how can I limit access to only one AD group?
Under advanced setting in Nebula for my AD server the is a "Group Membership Attribute:". This field is not anywhere in documentation so I don´t know if it can be used to setting the AD group. I have tried to enter the CN= string but it does not work. (I know it works if the firewall is not managed by Nebula).
Anyone?
All Replies
-
Hi @AndersW,
At present, it is not supported in the current design of NCC.
We will raise it as a feature request for future evaluation.
0 -
Really?😮
0 -
Yes this is a complete lack of a simple feature.
The nebula setup is missing the ability to chose the “External User Group” when setting up “Remote access VPN”
This is possible when the device is onprem managed.
There is a workaround. Create a Security policy to disable a specific AD group. But then you must maintain two AD groups (allow and deny). This is VERY bad workaround.
0
Categories
- All Categories
- 398 Beta Program
- 2.1K Nebula
- 117 Nebula Ideas
- 83 Nebula Status and Incidents
- 5.2K Security
- 99 USG FLEX H Series
- 247 Security Ideas
- 1.3K Switch
- 69 Switch Ideas
- 922 WirelessLAN
- 35 WLAN Ideas
- 5.9K Consumer Product
- 212 Service & License
- 337 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.1K FAQ
- 1K Nebula FAQ
- 445 Security FAQ
- 238 Switch FAQ
- 213 WirelessLAN FAQ
- 47 Consumer Product FAQ
- 142 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 72 About Community
- 62 Security Highlight