How to configure SonicWall Active Directory integration

  Рет қаралды 27,750

Jean-Pier Talbot

Jean-Pier Talbot

Күн бұрын

Пікірлер: 56
@DaleBentley-z3l
@DaleBentley-z3l Жыл бұрын
Hi Jean, excellent tutorial as always and appreciate you spending the time putting this together. Ran though LDAP setup initially, working well. Then tried next step of changing over to LDAPS with import of generated certificate from root.cer file, split DNS, etc. Test to server fails with "Error connecting to LDAP server Message returned from LDAP: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed (unable to get local issuer certificate)". Rechecked setup, certificate definitely imported correctly, DNS correct and can resolve server name, rewatched video again and all correct however continues to fail. Then after Google search found several people reporting same error and workaround was under LDPA Configuration, Settings, General Settings to uncheck "Require valid certificate from server when using TLS". Did this and now working with LDAPS. Any thoughts on why this is required and any issue unchecking this setting?
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
Thanks for your comment, I have pin it at the top for others to see. Honestly I’m really not an expert in certificate and in AD. Your googling will be as good as mine on that topic :-)
@DaleBentley-z3l
@DaleBentley-z3l Жыл бұрын
@@JeanPierTalbot My certificate skills probably similar to yours, however at least there is a workaround others may choose to use: uncheck "Require valid certificate from server when using TLS". From my reading the LDAP communication is still encrypted which is the most important thing. I am setting up a new SonicWall implementation next week and will be doing the same AD integration. Will report back if what happens in this case. Thank you once again for the excellent tutorials, looking forward to your upcoming topics (in particular Best practices re: logging, reports I hope)
@gavinchilds283
@gavinchilds283 Жыл бұрын
I had the same error, I resolved it by installing the root cert in addition to the server cert. I would expect the root cert alone is all that's required to authenticate the DC. I'm running my own domain joined CA Server, hence having a root cert.
@tommckeown6970
@tommckeown6970 7 ай бұрын
Thanks you for all the videos. Some of this is so complex that I would never have figured it out on my own. I appreciate all the details. Got me up and working.
@MicahW1
@MicahW1 3 жыл бұрын
This was incredibly useful! I am preparing to enable LDAPS, and your video confirmed I am going about it the correct way.
@JeanPierTalbot
@JeanPierTalbot 3 жыл бұрын
Glad it was helpful!
@wailakiyt
@wailakiyt 11 ай бұрын
Thanks Jean-Pierre! Really well done.
@MichaelKnichel
@MichaelKnichel Ай бұрын
Can we use MS 365 Azure/AD instead if we don't use a local AD server?
@joker_05194
@joker_05194 6 ай бұрын
Hii. I am having issue related to access rules with ad sso groups. Only first rule is working. And if create the rule with another group and put the rule at second number. The users goes to unauthenticated user. And in bracket showing cannot get the sso with 1st rule access group.
@jdej66339oa
@jdej66339oa 2 ай бұрын
I have a question for something I want to do and it's driving me crazy. There is a way to only allow domain joined computers to access the vpn? For example if an employee uses their personal computer , have the vpn to reject the connection because it's not part of out domain. Jose
@JeanPierTalbot
@JeanPierTalbot 2 ай бұрын
Not officially. Only the SSL appliances have EPC (end point control) firewalls don’t have EPC. BUT… while you can’t control what devices connect, you can control what devices passes traffic using SSO.
@marciocredes
@marciocredes 3 жыл бұрын
Hi Jean-Pier, In my case it happened with Microsoft AD itself. LDAP authorization is functional, but groups are with (MemberOf). I opened a call and I'm waiting.
@myscbees9041
@myscbees9041 10 ай бұрын
Jean-Pier. Hello. I have a question about 1 of the additional tips you shared. I am trying to create a rule which allow wan-lan for terminal services, with the snl in the middle validating internal groups. if i create the rule under https - then I can authenticate, but the terminal services don't work. If i create the terminal services connection but change the inbound rule (https to terminal services) I can not connect. if i allow the 'any' (w/o any type of ad group auth) for the terminal services - that works. I believe this used to work but doesn't now. is there a way to do this - use terminal services - from the wan - to a lan object, but require the snl to utilize ad integration for access? It would seem a simple thing to 'wrap' ad-auth against a inbound connection - that way the terminal server can be 'open' to the internet, but unless they authenticate the connection won't be made. thanks, mark
@JeanPierTalbot
@JeanPierTalbot 10 ай бұрын
Hi, I believe I showed exactly this scenario in my tip and trick video. It has to be a 2 steps thing. First, authenticate to the firewall on https with your AD user. Second, do a little inbound NAT for RDP and select your group in the « include user » Keep in mind. If the user is in the airport, then all the airport has access to RDP as this type of authentication simple link a WAN IP to a user. Best is to use a VPN client. See my SSL VPN video
@jayshah1992
@jayshah1992 Жыл бұрын
Hello sir, I tried exactly as you mentioned in the video. But it does not work. It keeps giving me the below error message when I press the test button. "Warning! LDAP can not be enabled in FIPS mode without a valid local certificate for TLS!". We already imported a certificate from our domain controller so not sure what the issue it. Any help in getting this to work will be greatly appreciated. Our firewall operates in FIPS mode.
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
Unfortunately I won’t be able to help out with the FIPS mode. Best would be to call support for help. Do you really need FIPS? Or you enabled it just because because ?
@jayshah1992
@jayshah1992 Жыл бұрын
@@JeanPierTalbot no problem. I got it figured out.
@chrisnino5442
@chrisnino5442 Жыл бұрын
I'm trying to set up the AD integration with LDAP for VPN access, but the UI for this SW FW is older and where you enter the username and the location is AD, it's one cell. I entered the object location from AD and modified the last entry to the user's name but I continue to get the error: Error: Credentials not valid at LDAP server - 80090308: LdapErr: DSID-0C090447, comment: AcceptSecurityContext error, data 52e, v3839 Can you provide any guidance? How can I update the UI? It is a licensed product.
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
Hi. I’m running the 7th generation of sonicwall product that were released maybe 3 years ago. If yours if a lot different, chances are you are on the previous generation. Sort term, you can upgrade to the latest release of gen6 (you can upgrade your current firewall to gen7 firmware) the latest gen6 firmware UI might be close enough. You may want to consider to upgrade your physical firewall to a gen7 unit. If you do a secure upgrade, the value of your remaining licences will transfer on your gen7 unit :-)
@rayalejandrogaviriaalegria5978
@rayalejandrogaviriaalegria5978 2 жыл бұрын
hello community, How do I encrypt the connection between the utm and the active directory?
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
LDAPS is implemented further in that video.
@garryhasty6594
@garryhasty6594 2 жыл бұрын
Love your videos Jean-Pier! I have a question, I was told you don't want to run Certificate Authority on your Domain Controller. I feel you are very knowledgeable, can you please clarify? MUCH APPRECIATED!
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
I believe I mentioned it in that video, or another… but I’m really not a Microsoft expect. For this video I installed a 2012 server and followed a video of « Eli the computer guy » on how to set AD. Last time in my carrer I deployed AD in production for a customer was with 2003 server… like 2 decades ago! Lol time flys! So I’ll let you research what is the best way to deploy any Microsoft things…
@garryhasty6594
@garryhasty6594 2 жыл бұрын
@@JeanPierTalbot A fair response Jean-Pier! Thank you for the reply!
@christianissa274
@christianissa274 4 жыл бұрын
Nice. Couple questions, for production use does the DC need to have another role for LDAP or best to spin off another server? Also what version of Sonic OS is this?
@JeanPierTalbot
@JeanPierTalbot 4 жыл бұрын
Hi Christian, I'm no where near an AD security expect. I'm using the domain admin as it's much simpler. but you can create a service account with read access and it should work: www.sonicwall.com/support/knowledge-base/integrating-ldap-active-directory-with-sonicwall-utm-appliance/170707170351983/ the firmware you see is the new sonicOS7. currently only available on TZ570 and TZ670
@boedillard8807
@boedillard8807 3 жыл бұрын
Thanks for the video. I'm looking at Radius to sonicwall as we are limited to 250 user accounts (not licenses but user accounts) on our sonicwall. I'm confused between this and radius and if there is an advantage to this vs. radius. Thanks in advance.
@henrymoisesmejia4583
@henrymoisesmejia4583 2 жыл бұрын
what to have present if needed that operate 2 server de AD, finally in a time one of this will disconect. and as it affects the setting that have VPN SSL.
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Simply add your second AD server in the list :-)
@sabelomnisi8647
@sabelomnisi8647 3 жыл бұрын
Great Video. Much appreciated . I have a question. I have windows AD setup and LDAP S has been configured on firewall. Im struggling with the login page. I can see user activity however I would like for AD and Local users to be redirected to a login page before being granted access. A group has been created that will be bypassed how ever I cant seem to get login page up and running,Please advise
@JeanPierTalbot
@JeanPierTalbot 3 жыл бұрын
Hi Sabelo, thanks for the feedback. I believe this is what you are looking for: www.sonicwall.com/support/knowledge-base/how-can-i-force-user-authentication-prior-to-allowing-traffic-through-the-firewall/170503559814835/
@simphiwemnisi1396
@simphiwemnisi1396 3 жыл бұрын
@@JeanPierTalbot Thank you for your response.
@simplyforgeahead
@simplyforgeahead 2 жыл бұрын
My current config uses local users. If I go ahead with ldap/ad will that remove the local users access? Just asking because I don't want to get rid of the local users until I know that the ldap works good thanks
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
In authentication menu, you can pick « local user / LDAP » that will use both.
@tophrob
@tophrob Жыл бұрын
I used your video to setup LDAP a while back, thanks for that. One strange thing that just started happening is my personal AD account is failing authentication, not allowing me to connecto thru our VPN. However...every other user in our VPN group CAN connect?! I'm perplexed! When i test my account from LDAP settings, I get authentication failed with the error 80090308: LdapErr: DSID-0C090434, comment: AcceptSecurityContext error, data 52f, v4f7c. I've looked that error up to no avail. Seems quite odd that it's just my account, no?!
@tophrob
@tophrob Жыл бұрын
I just found out the issue...my account is a member of the Protected Users group. Apparently that membership adds a level of security that doesnt allow LDAP authentication. Wondering if there's a solution other than removing myself from that group?
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
Good one. I have no clue. I was about to suggest calling support.
@tomlapaz1
@tomlapaz1 4 жыл бұрын
We have a SMA500v and instead of Microsoft AD we use OpenLdap. Authorization with LDAP is working but Groups are not (MemberOf). I opened a case with Sonicwall but until now they couldn’t find a solution. I don’t like that in most cases Ldap integration is based on Microsoft’s AD and not on open software.
@JeanPierTalbot
@JeanPierTalbot 4 жыл бұрын
Hi Thomas, please email me your ticket number.
@tomlapaz1
@tomlapaz1 4 жыл бұрын
@@JeanPierTalbot It is part of ticket # 43511827
@kumaran8203
@kumaran8203 Жыл бұрын
Can you pls share the process for adding Sonicwall GMS 9.3 into our existing NPS server through Radius
@JeanPierTalbot
@JeanPierTalbot Жыл бұрын
Hi, unfortunately GMS is on its last stretch, getting replaced by NSM. So I won’t do video on GMS
@justin-hall
@justin-hall 4 ай бұрын
2:28 Thank you!
@samu_el_pack
@samu_el_pack 2 ай бұрын
gracias
@JeanPierTalbot
@JeanPierTalbot Ай бұрын
Denada
@phillipank1213
@phillipank1213 3 жыл бұрын
Hi Jean-Pier, Very helpful and clear video! I got everything setup, and all tested successful, including secure ldap. But when I log in with an AD account, it shows not secure, and only displays a message about limit time remaining. I don't see any options to configure anything. Is there something else to set up? Thanks again!
@phillipank1213
@phillipank1213 3 жыл бұрын
I found the answer.
@rayalejandrogaviriaalegria5978
@rayalejandrogaviriaalegria5978 2 жыл бұрын
Hi, Jean,Is there a way to export the Active Directory certificate without being a certification authority ?
@JeanPierTalbot
@JeanPierTalbot 2 жыл бұрын
Unfortunately I’m really not a cert expert. Sorry
@rayalejandrogaviriaalegria5978
@rayalejandrogaviriaalegria5978 2 жыл бұрын
@@JeanPierTalbot tks, Is it possible to perform the operation from the sonicwall ? I mean that to the DA server I can install a certificate generated by the fw.
@JStevensdk7
@JStevensdk7 2 жыл бұрын
Yes you can probably use MAKECERT, but it is not very straightforward. I ended up just adding the CA role to one of my DC's. docs.microsoft.com/en-us/virtualization/community/team-blog/2013/20130413-hyper-v-replica-certificate-based-authentication-makecert
@dohc281
@dohc281 3 жыл бұрын
Doesn't the "Warning - LDAP should not be used without TLS other than for diagnostic purposes. This is highly insecure" cause you concern? Standard LDAP traffic is not encrypted.
@francismori7
@francismori7 3 жыл бұрын
Where are the next videos? :)
@JeanPierTalbot
@JeanPierTalbot 3 жыл бұрын
On the todo list… :-) (Assuming you are asking about SSO)
@mozenrathzerksis174
@mozenrathzerksis174 4 жыл бұрын
configure ldap on windows to make it full tutorial
How to configure SonicWall Single Sign On (SSO)
51:15
Jean-Pier Talbot
Рет қаралды 15 М.
SonicWall basic configuration step by step (part 1)
31:27
Jean-Pier Talbot
Рет қаралды 161 М.
БОЙКАЛАР| bayGUYS | 27 шығарылым
28:49
bayGUYS
Рет қаралды 1,1 МЛН
-5+3은 뭔가요? 📚 #shorts
0:19
5 분 Tricks
Рет қаралды 13 МЛН
How to configure SonicWall Intrusion Prevention Service (IPS)
11:38
Jean-Pier Talbot
Рет қаралды 10 М.
How to configure SonicWall DPI-SSL
25:10
Jean-Pier Talbot
Рет қаралды 17 М.
How to configure SonicWall client SSL VPN
11:41
Jean-Pier Talbot
Рет қаралды 42 М.
Fortigate Active Directory Integration
14:26
SinaOnline
Рет қаралды 19 М.
How to configure SonicWall Geo-IP filtering
17:26
Jean-Pier Talbot
Рет қаралды 7 М.
pfSense Alternatives: Firewall Solutions for your Network
12:27
VirtualizationHowto
Рет қаралды 17 М.
SonicWall switches - Basic step by step configuration
57:08
Jean-Pier Talbot
Рет қаралды 13 М.
pfSense CE vs OPNsense 2024 ...and that video
43:05
Sheridan Computers
Рет қаралды 15 М.
Azure: Site to Site VPN to Sonicwall how-to | step by step
15:54