Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
G_W_Albrecht
Legend Legend
Legend
Jump to solution

SMB Remote Access AD users

A customer reported that after updating the firmware from R77.20.75 to R77.20.8x on locally managed 730, RA VPN clients could no longer authenticate with AD credentials as the SMB GW did not communicate with the AD anymore. It needed an adjustment for different parsing of OUs in AD - but i could find no documentation or remark about this. Did anyone experience the same issue ?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
1 Solution

Accepted Solutions
G_W_Albrecht
Legend Legend
Legend

Customer explained that he originally had restricted the AD to a branch containing all windows user groups needing RA VPN access.

Now he had to use a OU branch containing also users from the AD VPN group.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

View solution in original post

0 Kudos
6 Replies
Mike_A
Advisor

Gunther,

We had this issue, it seemed to link with the firmware upgrade but in our instance it was related to the upgrade of the MDS from R77.30 to R80.10. LDAP (TCP389/636) was not sent across the tunnel but observed being sent out the WAN interface on the SMB device. After following sk92281 we were able to fix our issue. 

G_W_Albrecht
Legend Legend
Legend

That is surely a different issue and not connected to implied rules.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Mike_A
Advisor

You are correct. I saw the "clients could no longer authentication with AD" and immediately thought of the issue we had. Sorry to muddy the water. 

0 Kudos
Pedro_Espindola
Advisor

Local or central management?

G_W_Albrecht
Legend Legend
Legend

Cought me red-handed  - locally managed, i added that to the question...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
G_W_Albrecht
Legend Legend
Legend

Customer explained that he originally had restricted the AD to a branch containing all windows user groups needing RA VPN access.

Now he had to use a OU branch containing also users from the AD VPN group.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events