<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: NAC LDAP User Search Root in ExtremeWireless (Identifi)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-identifi/nac-ldap-user-search-root/m-p/40296#M2640</link>
    <description>Andre,&lt;BR /&gt;
&lt;BR /&gt;
The User Search Root will be the root node of the LDAP hierarchy that has all User DN's that you would need too be able to see with LDAP. If you're just trying to make sure a user is in a security group to access the wireless, you should create a rule that checks an LDAP End System group where the user has a memberOf attribute equal to CN=Wireless Users,OU=Security Groups,OU=Global Services,DC=X,DC=Y,DC=Z. If it doesn't match, then they would not match the rule.&lt;BR /&gt;
&lt;BR /&gt;
Does that help at all?&lt;BR /&gt;
&lt;BR /&gt;
Tyler&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Tue, 31 May 2016 21:54:00 GMT</pubDate>
    <dc:creator>TylerMarcotte</dc:creator>
    <dc:date>2016-05-31T21:54:00Z</dc:date>
    <item>
      <title>NAC LDAP User Search Root</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/nac-ldap-user-search-root/m-p/40295#M2639</link>
      <description>Hi &lt;BR /&gt;
&lt;BR /&gt;
I am trying to intergrate NAC into AD using LDAP.&lt;BR /&gt;
When adding the LDAP server you must specify a "User Sear Root".&lt;BR /&gt;
Does this location have to be a OU?&lt;BR /&gt;
The client I am configuring this for utilizes Security Groups, If I look at the attributes for the security group it looks as follows: CN=Wireless Users,OU=Security Groups,OU=Global Services,DC=X,DC=Y,DC=Z, Nac reports success but the user group is empty.&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="57ab8800f3354e90b56efb729006bbb9_RackMultipart20160531-109816-5xmx7l-ldap1_inline.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2076i66272EB5E35014D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="57ab8800f3354e90b56efb729006bbb9_RackMultipart20160531-109816-5xmx7l-ldap1_inline.jpg" alt="57ab8800f3354e90b56efb729006bbb9_RackMultipart20160531-109816-5xmx7l-ldap1_inline.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
If is use a OU group i works fine.&lt;BR /&gt;
&lt;BR /&gt;
Any idea?&lt;BR /&gt;
&lt;BR /&gt;
Thx&lt;BR /&gt;
Andre</description>
      <pubDate>Tue, 31 May 2016 17:47:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/nac-ldap-user-search-root/m-p/40295#M2639</guid>
      <dc:creator>Andre_Brits_Kan</dc:creator>
      <dc:date>2016-05-31T17:47:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC LDAP User Search Root</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/nac-ldap-user-search-root/m-p/40296#M2640</link>
      <description>Andre,&lt;BR /&gt;
&lt;BR /&gt;
The User Search Root will be the root node of the LDAP hierarchy that has all User DN's that you would need too be able to see with LDAP. If you're just trying to make sure a user is in a security group to access the wireless, you should create a rule that checks an LDAP End System group where the user has a memberOf attribute equal to CN=Wireless Users,OU=Security Groups,OU=Global Services,DC=X,DC=Y,DC=Z. If it doesn't match, then they would not match the rule.&lt;BR /&gt;
&lt;BR /&gt;
Does that help at all?&lt;BR /&gt;
&lt;BR /&gt;
Tyler&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 31 May 2016 21:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/nac-ldap-user-search-root/m-p/40296#M2640</guid>
      <dc:creator>TylerMarcotte</dc:creator>
      <dc:date>2016-05-31T21:54:00Z</dc:date>
    </item>
    <item>
      <title>RE: NAC LDAP User Search Root</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-identifi/nac-ldap-user-search-root/m-p/40298#M2642</link>
      <description>Andre,&lt;BR /&gt;
&lt;BR /&gt;
In your LDAP configuration, use:  DC=X,DC=Y,DC=Z for the user, host and ou search roots, then test.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 02 Jun 2016 16:30:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-identifi/nac-ldap-user-search-root/m-p/40298#M2642</guid>
      <dc:creator>Bill_Handler</dc:creator>
      <dc:date>2016-06-02T16:30:00Z</dc:date>
    </item>
  </channel>
</rss>

