
SANGFOR IAM v2.1 User Manual
158
The domain controller locates in the local area network, that is to say, PC1 and PC2 can log in to
the domain controller before authentication; the domain controller and IAM gateway device can
communicate
with
each
other,
so
that
the
domain
controller
can
send
the
successfully-authenticated user information to the IAM gateway device. The primary DNS of the
LAN user (PC) should be the same with the IP address of the domain controller.
Check [Enable Active Directory SSO] to activate this SSO function. Click <Help of SSO Usage>
to view the guide information of how to configure component mode of SSO.
Active Directory SSO falls into three types: one is to install a SSO script on the domain controller
to intercept the logon logs; the second one is to allocate SSO script by the domain controller; the
third one is to allocate SSO script by the domain controller and to send logon/logoff information
to the IAM gateway device. The last SSO should have the help of a listening port to intercept the
active directory SSO information (in the data) sent from the mirror port of the switch or from the
HUB.
7.2.2.1.1.
Install Component Mode
Enter the shared key in the text box followed [User component mode, please enter shared key],
ensuring that the key is the same with that configured in the SSO component of the domain
controller.
At the end of installing the SSO component of the domain controller, it requires typing IP address
of the IAM gateway device, shared key. The shared key must be the same with that configured on
the IAM gateway device; otherwise, the active directory SSO function will not work properly.
7.2.2.1.2.
AD Group Policy Mode
This mode can realize SSO with the help of group policy of the Active Directory. Configured
correctly, it will enable the user to automatically get WEB authentication fulfilled by the IAM