VPNSSL AD authentication problem

andrealemmi
andrealemmi Posts: 10  Freshman Member
First Comment Sixth Anniversary Nebula Gratitude

Good morning,I can't add an "ext-group-users" with AD authentication, in the access user to a vpnssl, I can insert a group that contains "ext-group-users" but I am not authenticated

All Replies

  • rv_faro
    rv_faro Posts: 3  Freshman Member
    First Comment Friend Collector

    Hi @andrealemmi ,

    I have exactly the same problem on a USG FLEX 700 (non "H") . This happens only with firmware version 5.40.

    up to firmware version 5.39.1 this works fine.

    with model USG FLEX 500 and Firmware 5.40 authentication works fine

    which model / firmware you have?

  • andrealemmi
    andrealemmi Posts: 10  Freshman Member
    First Comment Sixth Anniversary Nebula Gratitude

    I have a usg-flex100h with firmware V1.32(ABXF.0)

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,306  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @andrealemmi,

    Since this is USG FLEX H category, I assume your firewall is H series. I did a local lab that I can add an extent-group-user and use this user to connect SSL VPN. Do you add your user to SSL VPN > authentication > user list? You may follow this video to learn how to configure.

    https://jam.dev/c/14a321b4-acc0-434e-8fe6-b71503dc943a

    P.S. Currently, extent-group-user object is not selectable in the authentication user list. You need to create a group and add the user to this group.

    If your issue is on other setting/page, please describe more details and share some screenshot, so we can better know your issue and help to resolve.

    Zyxel Melen


  • andrealemmi
    andrealemmi Posts: 10  Freshman Member
    First Comment Sixth Anniversary Nebula Gratitude
    ext group users.JPG user group.JPG vpnssl config.JPG

    thanks for the reply.in the images the configuration of ext-group-users, group and vpn. if I do the user test on ext-group-users it tells me that the user belongs to the domain group, if I connect with openvpn it tells me authentication failed.