PDA

View Full Version : AD connector not showing all Users migrated from Netware 6.0


rreyes
09-17-2008, 04:36 AM
Hello all,
this is my first time in the forums, I have a weird issue which i'm worry because if this don't work my boss won't use untangle for our company which will be a pity because untangle is a great software, any way this is whats happening:
I have installed the ad connector and the policy manager trial when untangle pulls all the AD users won't show all the users no matter where I point it always doesn't show all the users in any container or OU, well so what I did was that if I create a new user and pull the list again the new user is shown in the list. well this is crazy all the communication between the untangle and ad server is ok the only difference in this AD setup is that all the AD info in our tree was migrated from netware 6.0 and I noticed that any user created before the migration are the one that untangle cannot see only anything created after the migration is shown on the list. have anybody seen this? is this a bug?
Please help I don't want to go with any other solution I rather have my boss pay for the Professional Package and not give the money away for a close solution.

thanks.

tbelote
09-17-2008, 12:30 PM
It does not show user accounts who are locked or have no password. This is the most common cause of this scenario. Does this seem to explain what you are seeing?

tbelote
09-17-2008, 12:31 PM
The policy manager of AD connector will work regardless of if the users show up in this list. The list is only for remote access portal.

amac
09-17-2008, 12:50 PM
How would the user names get assigned to the policy mapping without showing up in the name section of the ad test?

tbelote
09-17-2008, 12:52 PM
How would the user names get assigned to the policy mapping without showing up in the name section of the ad test?

Good point amac I had forgotten about that, it is obviously most convenient if they show up from AD, but you can also manually enter the names into the local directory.

rreyes
09-18-2008, 06:43 AM
Hello all, thanks for the reply...

"It does not show user accounts who are locked or have no password. This is the most common cause of this scenario. Does this seem to explain what you are seeing?"
this is not the case in my situation.

Originally Posted by amac View Post
How would the user names get assigned to the policy mapping without showing up in the name section of the ad test?
Good point amac I had forgotten about that, it is obviously most convenient if they show up from AD, but you can also manually enter the names into the local directory.

ok, so how creating user localy relates with active directory?
so If I understand even that the users are not being shown in the AD list you can add a user locally then untangle will map that user with AD?

thanks.

amac
09-18-2008, 11:40 AM
Just found this out, looks like untangle doesn't pick up users that have passwords that are set to never expire.... could that be it?

nbutterworth
10-27-2008, 08:22 AM
@amac: I doubt it. I'm having a similar issue where usernames that I know are in AD are not showing up in the UT AD list (including my own). My username is set to never expire the password, but our senior network engineer's password is set the same way, and his username shows up in the list.

Is there a limitation on the number of usernames returned in the LDAP queries from AD?

mdh
10-27-2008, 09:22 PM
The rules for who shows up:

1. Normal account
2. Non-expired account
3. Password is required
4. User must be able to change their own password
5. They cannot be locked out