- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-12-2017 09:26 AM
I have created an authentication profile utilizing a connection to the LDAP servers. When I try to add an Administrator I am unable to select this authentication profile from the drop down menu. All that is available is "none."
I think that my server and authentication profiles are set up correctly as I am able to test the authentication profile using the commend line as follows:
admin@ddc-rt-fw-vpn-q08-2 vsys1> test authentication authentication-profile Auth-LDAP username u0852540 password
Enter password :
Target vsys: vsys1
Do allow list check before sending out authentication request...
name "ad\u0852540" is in group "all"
Authentication to LDAP server at X.X.X.X for user "u0852540"
Egress: X.X.X.X
Type of authentication: GSSAPI
Starting LDAPS connection...
Succeeded to create a session with LDAP server
DN sent to LDAP server: CN=u0852540,OU=People,DC=ad,DC=XXX,DC=edu
User expires in days: never
Authentication succeeded for user "u0852540"
Any thoughts or suggestions would be greatly appreciated.
Thanks!!
12-13-2017 04:12 AM
I think you created the authentication profile in vsys1
administrators are system level, so they can only use authentication profiles that are 'shared'
12-13-2017 04:12 AM
I think you created the authentication profile in vsys1
administrators are system level, so they can only use authentication profiles that are 'shared'
12-13-2017 06:46 AM
Excellent advice! Problem solved!
For the record, I had to recreate my server profile in "shared" and then create a new authentication profile in "shared" as well. Once that was done I was able to create administrators using the "shared profile" and they were able to successfully log in.
Thanks so much for your help!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!