Got it

AD authentication for AC6005

Created: Feb 16, 2021 07:00:32Latest reply: Jul 31, 2021 05:03:40 349 8 0 0 0
  HiCoins as reward: 0 (problem unresolved)

hello

i want to configuer SSID authentication from active directory users can anyone clear the follwoing questions to me: 

1- i checked the docuementation but it said we cannot use AD with dot1x is is true?

2- i found the following example but it use MAC + AD so can we use only the AD ?

https://support.huawei.com/hedex/pages/EDOC1100064350AEI0130Q/07/EDOC1100064350AEI0130Q/07/resources/dc/dc_cfg_ad_0010.html?ft=0&fe=10&hib=8.1.24.3.9.5&id=EN-US_TASK_0233385926&text=Example%20for%20Configuring%20AD%20to%20Perform%20Authentication%20and%20Authorization&docid=EDOC1100064350


3- incase we can use only AD for authentication can we use the same previous example guide and just delete the MAC access profile cinfiguration


4- if the authentication profile configuered like the following will it work normally? or it must have mac access profile?

[AC] authentication-profile name p1
[AC-authentication-profile-p1] authentication-scheme authen-sch
[AC-authentication-profile-p1] authorization-scheme author-sch[
AC-authentication-profile-p1]  ad-server template1
[AC-authentication-profile-p1] quit


Featured Answers

Recommended answer

chenhui
Admin Created Feb 16, 2021 07:25:28

Hi,
1. I didn't find the corresponding description that you described in point 1.
2. No, AD server is not the only choice that you can use to authenticate the users with MAC, besides the AD server, LADP server is also a choice.
3. No, if you want to use the MAC address for authentication, the MAC address profile is necessary.
4. As described in point 3, the MAC access profile is necessary.
View more
  • x
  • convention:

user_3896063
user_3896063 Created Feb 16, 2021 07:30:01 (0) (0)
for point 1 it is mentioned on the notes for the link i shared (When AD authentication is used, the access authentication mode cannot be set to 802.1X authentication.
) now this is not my query my query is that i want to authenticate users by the AD can i do that? if yes please share me a guide as the one i found has the MAC+ AD and i want authentication with AD only not MAC  
chenhui
chenhui Reply user_3896063  Created Feb 16, 2021 07:50:32 (0) (0)
What is the credentials for the users?  
user_3896063
user_3896063 Reply chenhui  Created Feb 16, 2021 08:02:19 (0) (0)
user name and password stored on the AD  
chenhui
chenhui Reply user_3896063  Created Feb 16, 2021 08:25:22 (0) (0)
You can adjust the authentication scheme.  
user_3896063
user_3896063 Reply chenhui  Created Feb 16, 2021 11:58:20 (0) (0)
i created ad template and test aaa is ok then authentication and authrization schema and set the mode to AD and then created authentication profile bind it to the ad template and auth and authorization schemes after that created VAP and bind with ssid and security profile open and the authentication profile , however after bind the VAP to the AP group the SSID appear but any one can connect to it doesn't ask for US and PW , i don't know what could be the reason  
All Answers
Hi,
Kindly wait for a second, we'll feedback you ASAP.
View more
  • x
  • convention:

Hi,
1. I didn't find the corresponding description that you described in point 1.
2. No, AD server is not the only choice that you can use to authenticate the users with MAC, besides the AD server, LADP server is also a choice.
3. No, if you want to use the MAC address for authentication, the MAC address profile is necessary.
4. As described in point 3, the MAC access profile is necessary.
View more
  • x
  • convention:

user_3896063
user_3896063 Created Feb 16, 2021 07:30:01 (0) (0)
for point 1 it is mentioned on the notes for the link i shared (When AD authentication is used, the access authentication mode cannot be set to 802.1X authentication.
) now this is not my query my query is that i want to authenticate users by the AD can i do that? if yes please share me a guide as the one i found has the MAC+ AD and i want authentication with AD only not MAC  
chenhui
chenhui Reply user_3896063  Created Feb 16, 2021 07:50:32 (0) (0)
What is the credentials for the users?  
user_3896063
user_3896063 Reply chenhui  Created Feb 16, 2021 08:02:19 (0) (0)
user name and password stored on the AD  
chenhui
chenhui Reply user_3896063  Created Feb 16, 2021 08:25:22 (0) (0)
You can adjust the authentication scheme.  
user_3896063
user_3896063 Reply chenhui  Created Feb 16, 2021 11:58:20 (0) (0)
i created ad template and test aaa is ok then authentication and authrization schema and set the mode to AD and then created authentication profile bind it to the ad template and auth and authorization schemes after that created VAP and bind with ssid and security profile open and the authentication profile , however after bind the VAP to the AP group the SSID appear but any one can connect to it doesn't ask for US and PW , i don't know what could be the reason  
very good
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.