Wireless Access

Reply
Frequent Contributor II
Posts: 478
Registered: ‎03-15-2014

After integrating Controller with active Directory can I create roles based on AD group?

After integrating controller with active directory can I create roles based on active directory group membership for example

 

IT group can have full access to everything but  accountatnt have no access at all.

MVP
Posts: 4,232
Registered: ‎07-20-2011

Re: After integrating Controller with active Directory can I create roles based on AD group?

You can server derivation rules assigning a role based on a matching filter-Id configured in AD
Thank you

Victor Fabian
Lead Mobility Engineer @ Integration Partners
AMFX | ACMX | ACDX | ACCX | CWAP | CWDP | CWNA
MVP
Posts: 1,412
Registered: ‎11-30-2011

Re: After integrating Controller with active Directory can I create roles based on AD group?

can you do that with AD integration? i know you can with radius, but is that what the OP is asking?

MVP
Posts: 754
Registered: ‎03-25-2009

Re: After integrating Controller with active Directory can I create roles based on AD group?

[ Edited ]

You can't do that with straight up ldap as far as I know. EDIT: I stand corrected, see below.

You can however set up a radius server (Clearpass, NPS, .. ) and use that to return roles depending on AD group membership.

 

With an Aruba controller you can have your radius server return the aruba vsa aruba-user-role (amongs many more) to have this applied to the user. No need to go into server derivation rules and the likes even.

 

 

Koen (ACMX #351 | ACDX #547 | ACCP)

-- Found something helpful, important, or cool? Click the Kudos Star in a post.
-- Problem Solved? Click "Accept as Solution" in a post.
Guru Elite
Posts: 20,807
Registered: ‎03-29-2007

Re: After integrating Controller with active Directory can I create roles based on AD group?

Koenv

 

You can change a device's role  based on an attribute  in with LDAP:

 

http://community.arubanetworks.com/t5/ArubaOS-and-Controllers/LDAP-server-Server-Rules/m-p/2235/highlight/true#M461



Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Search Airheads
Showing results for 
Search instead for 
Did you mean: