AAA Server - AD user type
Accepted Solution
-
Hi @Datamail,
Yes, that's my understanding
My setup on USG FLEX 50 (firmware version 5.38) is using a domain users account on Domain Authentication for MSChap.By default, AD domain users member has privilege to add computer into the AD(Join Domain).
My IKEv2 VPN with EAP-CHAPv2 authentication works without issue.
0
All Replies
-
Hi @Datamail
Thank you for your inquiry. The Active Directory (AD) user cannot be a member of the administrator group. From the firewall's perspective, the AD user is considered an external user. Thanks.
0 -
Hi, thank you. I know that the AD user is considered as an external user. My question was, does this AD user must be an admin member of the Active Directory ? Or just a basic member.
In term of security, I don't want to enter this kind of user in the Zyxel firewall…
Thank you
0 -
Hi @Datamai
Thank you for your clarification. Currently, the AD user cannot log in to the firewall to edit any settings. Don't worry about it. Thanks.
0 -
My fear isn't that the AD user can or cannot log into the Zyxel, but I don't want that a vulnerability on the Zyxel could expose an AD user with privilege. All the AD informations and user password are entered on the Zyxel. Thanks
0 -
Hi, are you sure about it ? I noticed that I need an AD administrator for Domain Authentication for MSChap. If I enter a standard user, the vpn authentification fail.
Thank you
0 -
Hi @Datamail,
Yes, that's my understanding
My setup on USG FLEX 50 (firmware version 5.38) is using a domain users account on Domain Authentication for MSChap.By default, AD domain users member has privilege to add computer into the AD(Join Domain).
My IKEv2 VPN with EAP-CHAPv2 authentication works without issue.
0
Categories
- All Categories
- 398 Beta Program
- 2.1K Nebula
- 117 Nebula Ideas
- 83 Nebula Status and Incidents
- 5.2K Security
- 99 USG FLEX H Series
- 247 Security Ideas
- 1.3K Switch
- 69 Switch Ideas
- 923 WirelessLAN
- 35 WLAN Ideas
- 5.9K Consumer Product
- 212 Service & License
- 337 News and Release
- 71 Security Advisories
- 21 Education Center
- 5 [Campaign] Zyxel Network Detective
- 2.1K FAQ
- 1K Nebula FAQ
- 445 Security FAQ
- 238 Switch FAQ
- 213 WirelessLAN FAQ
- 47 Consumer Product FAQ
- 142 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 72 About Community
- 62 Security Highlight