Header Only - DO NOT REMOVE - Extreme Networks

Netsight LDAP Authentication of Groupmembers


Userlevel 2
Hello, I'm currently changing my Netsight-Authentication from OS to LDAP (MS Active Directory). I've 2 groups in AD. 1 for admins and 1 for operators. Is there a way to configure that all groupmembers have access to netsight with definded AuthorizationGroups in Netsight? I'm currently a bit confusing about situation.

8 replies

Userlevel 7
Here a link to the solution...
https://gtacknowledge.extremenetworks.com/articles/How_To/How-To-Match-NAC-LDAP-Lookup-To-Active-Dir...
Userlevel 2
Hi Ron, thanks for your reply, but it doesn't really help... because it shows NAC and not Netsight...But it helps thinking... "Membership Criteria" seems to be the field I need in Auth-Group configuration
Userlevel 6
Also see the following. I believe you will need the user setup in both parts, to get the 'separation' into different groups from Netsights point of view.
Userlevel 2
@Mike That meens, that I need to create user in "authorized Users" Tab in Netsight? Or is this only nessecary for local users?
Userlevel 6
No, it's needed for LDAP as well. We don't expect users to want anyone within an LDAP group to get access.
Userlevel 2
and still it works...
You do not need to create users in netsight...they will automatically added, if they are groupmembers in LDAP...
Userlevel 1
Peter wrote:

and still it works...
You do not need to create users in netsight...they will automatically added, if they are groupmembers in LDAP...

I've had the same problem but solved it. The correct membership criteria of the Authorization Group should be memberOf="DN of the AD Group". IMHO the instruction in the help is not very correct.
Userlevel 2
This function is not implemented very well...
I've a lot LDAP setups at customers but sometimes the automatic groubmembership is not working, but I don't understand why.... When I add user to ldap group in netsight, it works... but this is not the function I will have.

Some Ideas, why this wouldn't work every time?

Reply