cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

Dynamic Administrator Authentication based on Active Directory Group rather than named users?

L1 Bithead

Hello,

 

We have an environment with several adminstrators from a rotating NOC. With the current LDAP method to my understanding we have to manually add the administrator name to the PA administrators list before login will work (e.g. jdoe). We would like to be able to tie it to an AD group (e.g. "Firewall Admins") so anyone who is a member of that group will get access with no further configuration. This is possible in pretty much all other systems we work with (Cisco ASA, etc.)

 

My research has led that this isn't possible with LDAP but might be possible with RADIUS/NPS and attributes (which I'm comfortable with setting up)

 

Before I go to the trouble, do I still have to manually add named administrators to the firewall config with the RADIUS setup, or will they be autocreated? (e.g. if I log in as "jdoe" to the firewall and have never logged in before or added him as an administrator, as long as he is a member of "Firewall Admins" he will get access to the firewall with the access class defined in his RADIUS attribute)?

 

Thanks for any assistance.

Who rated this post