AAA Server - AD user type
Accepted Solution
-
Hi @Datamail,
Yes, that's my understanding
My setup on USG FLEX 50 (firmware version 5.38) is using a domain users account on Domain Authentication for MSChap.By default, AD domain users member has privilege to add computer into the AD(Join Domain).
My IKEv2 VPN with EAP-CHAPv2 authentication works without issue.
0
All Replies
-
Hi @Datamail
Thank you for your inquiry. The Active Directory (AD) user cannot be a member of the administrator group. From the firewall's perspective, the AD user is considered an external user. Thanks.
0 -
Hi, thank you. I know that the AD user is considered as an external user. My question was, does this AD user must be an admin member of the Active Directory ? Or just a basic member.
In term of security, I don't want to enter this kind of user in the Zyxel firewall…
Thank you
0 -
Hi @Datamai
Thank you for your clarification. Currently, the AD user cannot log in to the firewall to edit any settings. Don't worry about it. Thanks.
0 -
My fear isn't that the AD user can or cannot log into the Zyxel, but I don't want that a vulnerability on the Zyxel could expose an AD user with privilege. All the AD informations and user password are entered on the Zyxel. Thanks
0 -
Hi, are you sure about it ? I noticed that I need an AD administrator for Domain Authentication for MSChap. If I enter a standard user, the vpn authentification fail.
Thank you
0 -
Hi @Datamail,
Yes, that's my understanding
My setup on USG FLEX 50 (firmware version 5.38) is using a domain users account on Domain Authentication for MSChap.By default, AD domain users member has privilege to add computer into the AD(Join Domain).
My IKEv2 VPN with EAP-CHAPv2 authentication works without issue.
0
Categories
- All Categories
- 426 Beta Program
- 2.6K Nebula
- 163 Nebula Ideas
- 112 Nebula Status and Incidents
- 6K Security
- 346 USG FLEX H Series
- 290 Security Ideas
- 1.5K Switch
- 78 Switch Ideas
- 1.2K Wireless
- 42 Wireless Ideas
- 6.6K Consumer Product
- 261 Service & License
- 404 News and Release
- 87 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.8K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 82 Security Highlight