724-746-5500 | blackbox.com
724-746-5500 | blackbox.com
Page 175
Chapter 11: Deployment Examples CLI
Password: Enter the password that the SmartPath AP RADIUS server supplies when requesting a user account lookup on the
Active Directory server. The password must exactly match the password entered for the user account defined on the Active
Directory server for the SmartPath AP RADIUS server. It can be up to 64 characters long. To ensure accuracy, enter the password
again in the Confirm Password field. To see the text string that you type, clear the Obscure Password checkbox.
After you enter the appropriate domain user credentials, click “Test Authentication.” SmartPath EMS VMA submits its domain
user name and password to authenticate itself. If successful, the following message appears: "The user was successfully authenti-
cated." In addition, the Multiple Domain Info section appears. You can define up to eight Active Directory domains in one or
more forests in which SmartPath AP RADIUS servers can perform user lookups. The domain you define first—before adding oth-
ers—is the default domain and indeed is identified as such by the section heading, Default Domain.
Multiple Domain Info
A SmartPath AP RADIUS server can support authentication lookups of users in up to eight Active Directory domains in one or
more forests. To add a domain, click “New,” enter the following, and then click “Apply:”
Domain: Enter the Windows domain name to which the SmartPath AP RADIUS authentication server and Active Directory server
both belong. This must not include any parent domains, such as .com, .net, .org, and so on. The domain name can be up to 64
characters long.
Full Name: Enter the complete Windows DNS domain name, including parent domains. For example, if the domain is "blackbox"
and it is a child domain of "com", then enter "blackbox.com" here. The full domain name can be up to 64 characters long.
Active Directory Server: Enter the IP address or resolvable domain name of the Active Directory server that contains the user
accounts you want the SmartPath AP RADIUS authentication server to authenticate. The server domain name can be up to 64
characters long.
Domain User: Enter the name that the SmartPath AP RADIUS server provides to authenticate itself to the Active Directory server
when initiating a connection to request a user account lookup. The form of the name must match the form that appears as an
entry on the Active Directory server. For example, the entry name might be "clusterap1" and be located in the LDAP directory
structure at "cn=clusterap1,cn=admins,cn=users,dc=blackboxblackboxblackboxblackbox,dc=com". It might also be in e-mail
format, such as "[email protected]," for example. It can be up to 256 characters long.
Password: Enter the password that the SmartPath AP RADIUS server supplies when requesting a user account lookup on the
Active Directory server. The password must exactly match the password entered for the user account defined on the Active
Directory server for the SmartPath AP RADIUS server. It can be up to 64 characters long. To ensure accuracy, enter the password
again in the Confirm Password field. To see the text string that you type, clear the Obscure Password checkbox.
Step 2: Configure SmartPath AP RADIUS Server Settings that Reference the Active Directory Settings
Click “Configuration > Advanced Configuration > Authentication > SmartPath AP AAA Server Settings > New,” enter the
following, and then click “Save:”
Name: Type a name for this configuration. It can be up to 32 characters long and cannot contain spaces.
Description: Type a note about the configuration for later reference. It can be up to 64 characters long, including spaces.
Expand the Database Access Settings section, and select Active Directory. From the Active Directory drop-down list, choose the
name of the Active Directory settings that you created on the AAA User Directory Settings page above. From the Server Role
drop-down list, choose Primary. Then click “Apply.”
Select LDAP server attribute mapping. A new section expands. You have the option of manually mapping LDAP user groups to
local user profiles or automatically mapping LDAP user groups to user profiles through the use of matching attributes.
Manually map LDAP user groups to user profiles: Select this option to display the Active Directory domain and LDAP directory
structure retrieved from the server so that you can make a direct, static map of LDAP user groups (or OUs) on the Active Directory
server to user profiles on SmartPath AP RADIUS authenticators.