| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Whilst implementing LDAP integration with NGAI R55 I have come across a problem with the firewall not reading the MS AD security groups which I have defined for my SecureClient users. If I put the AD users in the default container 'users' I can remote in and get authenticated etc. If however, I place the user in a AD security group within the 'users' container it fails. Everything seems to be in place, I can fetch the branch and view the securtiy group and see the user ID's in it etc. but as mentioned earlier as soon as I try and login/authenticate if fails . Would be grateful for any ideas. regards |
| |||
| Did you create an LDAP group for secureclient users. By picking a specific group within an LDAP branch. I have been using AD since FP3 + win2k (management server is linux). We are now at NGX + win2k3 with no problems. Try creating a LDAP group that points directly to the CN on the group you want to authenticate from. |
| |||
| Few weeks ago I'm accidentally found in CheckPoint documentation interesting thing. It is possible to map Radius users to checkpoint groups. Before I thought that radius users can only be mapped to one generic* user. This can by done via RAD_<group to which the RADIUS users belong>. This feature did not require LDAP license (this license not a problem for all-included license holders). Quote:
|
| |||
| Gotcha!!! If you a have lot of OU in your Active Directory you need to add each OU (where users is located) in the branch. Checkpoint check the credential first... After it check if the user is located in the LDAP Group (AD Group) Marc |
| |||
| hello sergej, thats exactly what i'm looking for :-))) could you give me some hints or tell me where esactly in the documents you found this. thx a lot, stef Quote:
|
| |||
| Quote:
|
| |||
| Quote:
i know i'm too stupid, but could someone please explain me, howto access an document directly. if i change the sk# in the url, i get a blabla-page. regards, stef |
![]() |
| Thread Tools | |
| Display Modes | |
| |