AAA Server - AD user type
Accepted Solution
-
Hi @Datamail,
Yes, that's my understanding
My setup on USG FLEX 50 (firmware version 5.38) is using a domain users account on Domain Authentication for MSChap.By default, AD domain users member has privilege to add computer into the AD(Join Domain).
My IKEv2 VPN with EAP-CHAPv2 authentication works without issue.
0
All Replies
-
Hi @Datamail
Thank you for your inquiry. The Active Directory (AD) user cannot be a member of the administrator group. From the firewall's perspective, the AD user is considered an external user. Thanks.
Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community
0 -
Hi, thank you. I know that the AD user is considered as an external user. My question was, does this AD user must be an admin member of the Active Directory ? Or just a basic member.
In term of security, I don't want to enter this kind of user in the Zyxel firewall…
Thank you
0 -
Hi @Datamai
Thank you for your clarification. Currently, the AD user cannot log in to the firewall to edit any settings. Don't worry about it. Thanks.
Share your feedback through our survey, make your voice heard, and win a WiFi 7 AP! https://bit.ly/2024_Survey_Community
0 -
My fear isn't that the AD user can or cannot log into the Zyxel, but I don't want that a vulnerability on the Zyxel could expose an AD user with privilege. All the AD informations and user password are entered on the Zyxel. Thanks
0 -
Hi, are you sure about it ? I noticed that I need an AD administrator for Domain Authentication for MSChap. If I enter a standard user, the vpn authentification fail.
Thank you
0 -
Hi @Datamail,
Yes, that's my understanding
My setup on USG FLEX 50 (firmware version 5.38) is using a domain users account on Domain Authentication for MSChap.By default, AD domain users member has privilege to add computer into the AD(Join Domain).
My IKEv2 VPN with EAP-CHAPv2 authentication works without issue.
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 144 Nebula Ideas
- 94 Nebula Status and Incidents
- 5.6K Security
- 237 USG FLEX H Series
- 267 Security Ideas
- 1.4K Switch
- 71 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.3K Consumer Product
- 247 Service & License
- 384 News and Release
- 83 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.2K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 83 About Community
- 71 Security Highlight