Controllerless Networks

last person joined: 3 days ago 

Instant Mode - the controllerless Wi-Fi solution that's easy to set up, is loaded with security and smarts, and won't break your budget
Expand all | Collapse all

IAP+LDAP

This thread has been viewed 15 times
  • 1.  IAP+LDAP

    Posted Mar 22, 2017 12:21 PM

    Hi guys,

     

    I have a issue. I've got LDAP authentication working but i need to point to the specific CN for Base-DN (See below).

     

    The thing is the AD has all the users scattered across a _lot_ of OUs and this is a problem for me. If I remove CN=Users and leave DC=xxx,DC=com then it won't work.

     

    Is there any way to recurse through the entire AD and if there is what should be in the Base-DN.

     

    Also, the GTC token thing doesn't work for Windows 10. In Windows 7 I'm able to authenticate but the connection will fail in Windows 10. Some assistance here would be much appreciated :)

     

     

    Thanks in advance!

     

    Daniel

     

     

     

     



  • 2.  RE: IAP+LDAP

    EMPLOYEE
    Posted Mar 22, 2017 01:56 PM

    You would deal with a majority of your issues (having to install EAP-GTC, having to figure out what container to authenticate users to), if you switch to using a radius server, instead...

     

    Typically you should just be able to use DC=Com, DC=Domain, but you might have to enable ldap debugging on your LDAP server to determine what is wrong.

     

    Again, switching to radius for 802.1x is a better way to do encryption and it provides more opportunities for troubleshooting.

     



  • 3.  RE: IAP+LDAP

    Posted Mar 23, 2017 04:32 AM

    Hi Colin,

     

    Thanks for replying. However the end does not want to use a Radius... we got to find a way to recurse through the OUs somehow.



  • 4.  RE: IAP+LDAP

    Posted Mar 26, 2017 10:46 AM

    Anyone has any ideas? Since the end user doesn't want a radius server...

     

    Any assistance greatly appreciated.

     

    TIA :)



  • 5.  RE: IAP+LDAP

    EMPLOYEE
    Posted Mar 26, 2017 12:09 PM

    Well,

     

    I am waiting for someone who still uses LDAP to answer...



  • 6.  RE: IAP+LDAP

    Posted Mar 26, 2017 01:36 PM

    yea i know it's a long shot, but it's worth a try......

     

    thanks Colin. appreciate it.



  • 7.  RE: IAP+LDAP

    Posted Apr 11, 2017 01:11 AM

    You can try using the plugin ldp.exe to find out the base DN for the OU you are interested in & then check if that helps



  • 8.  RE: IAP+LDAP

    Posted Apr 20, 2017 02:14 AM

    thanks...