cancel
Showing results for 
Search instead for 
Did you mean: 

Problem Importing Groups into Server Catalog

SOLVED
RB26DETT_
Occasional Contributor

Problem Importing Groups into Server Catalog

We are having issues pulling group memberships out of AD - during a capture I noticed the groups were pulled successfully from the primary DC, but then the appliance tries to connect to a few of our child domains which we have blocked by firewall policy.  We don't' have the child domains defined anywhere - is this typical behavior?  After it times out, none of the groups that it learned from the primary DC show up in server catalog.

 

 

1 ACCEPTED SOLUTION

Accepted Solutions
zanyterp_
Respected Contributor

Re: Problem Importing Groups into Server Catalog

Ok; then it is the referral response that must be chased to follow the LDAP spec. Is it possible to narrow down where you are looking more?

View solution in original post

7 REPLIES 7
zanyterp_
Respected Contributor

Re: Problem Importing Groups into Server Catalog

If you have the option to allow trusted domains enabled, yes, this is normal & expected.

Another way that this could happen is if there is a referral on the response from the server. If this happens, the IVE/MAG will reach out to the servers/domains that are required by the referral from the DC.

RB26DETT_
Occasional Contributor

Re: Problem Importing Groups into Server Catalog

Zanyterp,

 

Thanks for the reply.  I have it defined as an LDAP server instead of AD so the allow trusted domain option wasn't available.  I'll reach out to our server guy regarding the referral.

 

zanyterp_
Respected Contributor

Re: Problem Importing Groups into Server Catalog

Ok; then it is the referral response that must be chased to follow the LDAP spec. Is it possible to narrow down where you are looking more?
RB26DETT_
Occasional Contributor

Re: Problem Importing Groups into Server Catalog

You are right, we narrowed down our group search filter yesterday to only search the container holding our group memberships and it's no longer reaching out to the child domains.

 

We've run across another issue though and I'm hoping you might be able to help; the SA sits in one environment, and we have a one-way trust relationship with another DC in a separate forest.  I'm able to authenticate users in the local domain on the appliance but not from the trusted domain.  According to JTAC, authentication with AD using cross-forest trust is not supported.

 

Is it possible to define a RADIUS server as auth, and still use LDAP as the authorization server to pull group memberships?  I'm a bit cloudy on how the group fetching wil work when using RADIUS, or if you have any other suggestions that would be great.

zanyterp_
Respected Contributor

Re: Problem Importing Groups into Server Catalog

You can do that as long as the usernames are identical. But you will run into the same issue: it is not possible to do cross-forest/domain authentication/authorization with the LDAP server type
RB26DETT_
Occasional Contributor

Re: Problem Importing Groups into Server Catalog

Yeah we found that out the hard way.  A JTAC rep suggested that cross-forst trust is possible using a two-way trust - have you ever tried that?  Just trying to wrap my head around why the appliance would care of the the trust was one vs two way.

 

 

zanyterp_
Respected Contributor

Re: Problem Importing Groups into Server Catalog

I have & cross-forest auth isn't supported. You can cross domains, sometimes, using the global catalog port (3269/3268) rather than LDAP(S), but still hit & miss