Old 08-24-2010, 11:45 AM   #1 (permalink)
Newbie
 
Join Date: Jun 2010
Posts: 3
stictx is on a distinguished road
Default AD Problems multi site

I am a local franchisee with 11 locations. My parent company hosts AD and is the domain admin. I have no access to the domain but my user login. All of my users login to the domain. In order for me to use the AD connection I need to have admin access to the AD server which I don’t have.

I'm trying to use UT for content filtering specifically. When I attempt to login to the domain my login hangs for about 20 minutes. Once I get logged in all of my apps work great. In fact the citrix works better than outside the UT box.

What options do I have?
stictx is offline  
Old 08-24-2010, 12:04 PM   #2 (permalink)
Untangle Ninja
 
mrunkel's Avatar
 
Join Date: Jul 2008
Posts: 2,766
mrunkel is on a distinguished road
Default

You don't need admin access. It just queries the user and group list which is usually available to all users.

You do need non-encrypted LDAP access.
__________________
m.


Big Frickin Disclaimer:
While I'm pretty sure, I can't guarantee that I know what I'm doing. There might be a better way to do this, and this way might actually suck. Make sure you understand the implications of what you're doing before trying to follow these directions.

It often helps troubleshooting if you have a good network map. Look here if you want my advice on how to draw one.
Attention: Support and help on the Untangle Forums is provided by volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
mrunkel is offline  
Old 08-30-2010, 02:15 PM   #3 (permalink)
Newbie
 
Join Date: Jun 2010
Posts: 3
stictx is on a distinguished road
Default

I contacted my application vendor and they use encrypted LDAP access. Am I SOL or what options do I have.
stictx is offline  
Old 08-30-2010, 02:25 PM   #4 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

You'll have to switch over to Captive Portal authentication, and more than likely you'll have to stop authenticating against AD.

Nothing outside of a windows OS can get encrypted access to AD.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 08-30-2010, 02:37 PM   #5 (permalink)
Newbie
 
Join Date: Jun 2010
Posts: 3
stictx is on a distinguished road
Default

If I dont controll the AD server nor the domain I dont know that a captive portal will work for me. Would I need to create a new AD server?
stictx is offline  
Old 08-30-2010, 03:09 PM   #6 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,454
sky-knight is on a distinguished road
Default

The captive portal can authenticate vs a local directory, and at least give you some names to map to IP addresses.

But yes if you want AD and they require encrypted access... you'll have to build your own AD.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:33 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2