Network Management

last person joined: 3 days ago 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

LDAP Authentication to Airwave Questions

This thread has been viewed 14 times
  • 1.  LDAP Authentication to Airwave Questions

    Posted Aug 07, 2018 02:57 PM

     

    1. Is it possible to have both RADIUS and LDAP Authentication working on the same Airwave server?
    2. Is LDAPS (LDAP over SSL) supported?
    3. Can you use a different port (636 instead of 389) for LDAPS?

    Thanks.

    Neil



  • 2.  RE: LDAP Authentication to Airwave Questions

    EMPLOYEE
    Posted Aug 07, 2018 11:08 PM

    1) Yes, you can do multiple remote access servers.  The order will be RADIUS:TACACS:LDAP:LocalDB when remote auth is preferred.  Known feature request to allow choosing the order, not enough customer interest to push it beyond the Product team.

     

    2) Yes, LDAP-S is supported, with option to validate server certs.

     

    3) Yes, you can choose different port.

     

    This is all controlled from the AMP Setup -> Authentication tab.



  • 3.  RE: LDAP Authentication to Airwave Questions
    Best Answer

    Posted Aug 16, 2018 03:53 PM

    Here is the solution I worked out with TAC.

     

    1. You can only have ONE authentication method enabled at a time.
      So I had to Disable RADIUS authentication because I wanted to use LDAP. I was hoping to use both because our Network team prefers using RADIUS to authenticate, but our Help Desk uses LDAP.

    2. You must use LDAP with start-tls or clear-text authentication.
      If I try to use ldap-s the AMP server doesn't even initiate any outbound traffic to the LDAP server.

    3. You must use the fully qualified BIND DN name. user@ldapserver.com doesn't work.
    4. Make sure the account .you are logging  in with is in the right search DN.

    That's it. Everything is working now (except for RADIUS authentication).

     

    -Neil