Active Directory
In Active Directory, objects are organized in a number of levels such as domains, trees
and forests. At the top of the structure is the forest. A forest is a collection of multiple
trees that share a common global catalog, directory schema, logical structure, and
directory configuration. In a multi-domain forest, each domain contains only those items
that belong in that domain. Global Catalog servers provide a global list of all objects in
a forest.
ZoneDirector support for Active Directory authentication includes the ability to query
multiple Domain Controllers using Global Catalog searches. To enable this feature, you
will need to enable Global Catalog support and enter an Admin DN (distinguished name)
and password.
Depending on your network structure, you can configure ZoneDirector to authenticate
users against an Active Directory server in one of two ways:
• Single Domain Active Directory Authentication
• Multi-Domain Active Directory Authentication
Single Domain Active Directory Authentication
To enable Active Directory authentication for a single domain:
1.
Go to
Configure
>
AAA Servers
, and click
Create New
under
Authentication/Accounting Servers
. The
Create New
form appears.
2.
In
Type
, Select
Active Directory
.
• In Encryption, select Enable TLS encryption if you want to encrypt all authentication
traffic between the client and the Active Directory server. The AD server must
support TLS1.0/TLS1.1/TLS1.2.
3.
Do not enable
Global Catalog
support.
4.
Enter the
IP address
and
Port
of the AD server. The default Port number (389, or
636 if you have enabled TLS encryption) should not be changed unless you have
configured your AD server to use a different port.
5.
Enter the
Windows Domain Name
(e.g., domain.ruckuswireless.com).
6.
Click
OK
.
Ruckus Wireless ZoneDirector™ Release 10.0 User Guide
88
Configuring Security and Other Services
Using an External AAA Server