<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WiNG 7.5.1 LDAP cannot join to Windows Active Directory Domain 2016. in ExtremeWireless (WiNG)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-7-5-1-ldap-cannot-join-to-windows-active-directory-domain/m-p/86611#M8092</link>
    <description>&lt;P&gt;&lt;BR /&gt;WiNG 7.5.1 LDAP can not join to Windwdows Active Directory 2016. The configuration is below. Can Anybody help?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;radius-server-policy default&lt;BR /&gt;&amp;nbsp;authentication data-source ldap&amp;nbsp;&lt;BR /&gt;&amp;nbsp;authentication eap-auth-type peap-mschapv2&lt;BR /&gt;&amp;nbsp;ldap-server primary host 172.16.4.140 port 389 login "(sAMAccountName=%{Stripped-User-Name:-%{User-Name}})" bind-dn "CN=administrator,CN=Users,DC=shareweb,DC=net,DC=pa" base-dn "DC=shareweb,DC=net,DC=pa" passwd 0 hidden passwd-attr UserPassword group-attr cn group-filter "(|(&amp;amp;(objectClass=group)(member=%{Ldap-UserDn}))(&amp;amp;(objectClass=GroupOfUniqueNames)(uniquemember=%{Ldap-userDn})))" group-membership radiusGroupName net-timeout 10&lt;BR /&gt;&amp;nbsp;ldap-agent primary domain-name shareweb domain-admin-user Administrator domain-admin-password 0 hidden&lt;BR /&gt;&amp;nbsp;no ldap-group-verification&lt;/P&gt;&lt;P&gt;profile ap410 default-ap410&lt;BR /&gt;&amp;nbsp;ip name-server 172.16.4.140&lt;BR /&gt;&amp;nbsp;ip name-server 172.16.4.141&lt;BR /&gt;&amp;nbsp;ip domain-name shareweb.net.pa&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1-ap410-FF2A10#ping shareweb.net.pa&lt;BR /&gt;PING shareweb.net.pa (172.16.4.140) 100(128) bytes of data.&lt;BR /&gt;108 bytes from dc1.shareweb.net.pa (172.16.4.140): icmp_seq=1 ttl=128 time=0.342 ms&lt;BR /&gt;108 bytes from dc1.shareweb.net.pa (172.16.4.140): icmp_seq=2 ttl=128 time=0.286 ms&lt;BR /&gt;108 bytes from dc1.shareweb.net.pa (172.16.4.140): icmp_seq=3 ttl=128 time=0.317 ms&lt;BR /&gt;108 bytes from dc1.shareweb.net.pa (172.16.4.140): icmp_seq=4 ttl=128 time=0.325 ms&lt;BR /&gt;108 bytes from dc1.shareweb.net.pa (172.16.4.140): icmp_seq=5 ttl=128 time=0.322 ms&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1-ap410-FF2A10#show ldap-agent join-status&amp;nbsp;&lt;BR /&gt;Primary LDAP Server's agent join-status : Unable to find a suitable server for domain shareweb.net.pa&lt;BR /&gt;Unable to find a suitable server for domain shareweb.net.pa&lt;BR /&gt;Secondary LDAP Server's agent join-status : Not Configured or Unused&lt;/P&gt;</description>
    <pubDate>Sun, 31 Jan 2021 13:34:31 GMT</pubDate>
    <dc:creator>NoufalQA</dc:creator>
    <dc:date>2021-01-31T13:34:31Z</dc:date>
    <item>
      <title>WiNG 7.5.1 LDAP cannot join to Windows Active Directory Domain 2016.</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-7-5-1-ldap-cannot-join-to-windows-active-directory-domain/m-p/86611#M8092</link>
      <description>&lt;P&gt;&lt;BR /&gt;WiNG 7.5.1 LDAP can not join to Windwdows Active Directory 2016. The configuration is below. Can Anybody help?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;radius-server-policy default&lt;BR /&gt;&amp;nbsp;authentication data-source ldap&amp;nbsp;&lt;BR /&gt;&amp;nbsp;authentication eap-auth-type peap-mschapv2&lt;BR /&gt;&amp;nbsp;ldap-server primary host 172.16.4.140 port 389 login "(sAMAccountName=%{Stripped-User-Name:-%{User-Name}})" bind-dn "CN=administrator,CN=Users,DC=shareweb,DC=net,DC=pa" base-dn "DC=shareweb,DC=net,DC=pa" passwd 0 hidden passwd-attr UserPassword group-attr cn group-filter "(|(&amp;amp;(objectClass=group)(member=%{Ldap-UserDn}))(&amp;amp;(objectClass=GroupOfUniqueNames)(uniquemember=%{Ldap-userDn})))" group-membership radiusGroupName net-timeout 10&lt;BR /&gt;&amp;nbsp;ldap-agent primary domain-name shareweb domain-admin-user Administrator domain-admin-password 0 hidden&lt;BR /&gt;&amp;nbsp;no ldap-group-verification&lt;/P&gt;&lt;P&gt;profile ap410 default-ap410&lt;BR /&gt;&amp;nbsp;ip name-server 172.16.4.140&lt;BR /&gt;&amp;nbsp;ip name-server 172.16.4.141&lt;BR /&gt;&amp;nbsp;ip domain-name shareweb.net.pa&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1-ap410-FF2A10#ping shareweb.net.pa&lt;BR /&gt;PING shareweb.net.pa (172.16.4.140) 100(128) bytes of data.&lt;BR /&gt;108 bytes from dc1.shareweb.net.pa (172.16.4.140): icmp_seq=1 ttl=128 time=0.342 ms&lt;BR /&gt;108 bytes from dc1.shareweb.net.pa (172.16.4.140): icmp_seq=2 ttl=128 time=0.286 ms&lt;BR /&gt;108 bytes from dc1.shareweb.net.pa (172.16.4.140): icmp_seq=3 ttl=128 time=0.317 ms&lt;BR /&gt;108 bytes from dc1.shareweb.net.pa (172.16.4.140): icmp_seq=4 ttl=128 time=0.325 ms&lt;BR /&gt;108 bytes from dc1.shareweb.net.pa (172.16.4.140): icmp_seq=5 ttl=128 time=0.322 ms&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1-ap410-FF2A10#show ldap-agent join-status&amp;nbsp;&lt;BR /&gt;Primary LDAP Server's agent join-status : Unable to find a suitable server for domain shareweb.net.pa&lt;BR /&gt;Unable to find a suitable server for domain shareweb.net.pa&lt;BR /&gt;Secondary LDAP Server's agent join-status : Not Configured or Unused&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2021 13:34:31 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-7-5-1-ldap-cannot-join-to-windows-active-directory-domain/m-p/86611#M8092</guid>
      <dc:creator>NoufalQA</dc:creator>
      <dc:date>2021-01-31T13:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: WiNG 7.5.1 LDAP cannot join to Windows Active Directory Domain 2016.</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-wing/wing-7-5-1-ldap-cannot-join-to-windows-active-directory-domain/m-p/86612#M8093</link>
      <description>&lt;P&gt;Hi&amp;nbsp;Noufal,&lt;/P&gt;&lt;P&gt;Since you have posted limited details on your AD domain structure, I am responding with few assumptions.&amp;nbsp;There could be multiple reasons for it to fail, two of the most common ones are the Bind DN configuration and insufficient permissions on the Bind&amp;nbsp;User.&lt;/P&gt;&lt;P&gt;The Bind DN configuration will vary depending on where the Bind User account is created in the Active Directory tree. For smaller environments, the Bind DN will typically be located in the default Users container such as cn=username,cn=Users,dc=example,dc=com where the Users container is designated as a Common Name (CN).&lt;BR /&gt;However, in larger Active Directory environments the Bind User account will typically be located in an Organization Unit (OU). One common configuration error is to designate the OU as a CN. For example,&amp;nbsp;one&amp;nbsp;may incorrectly enter cn=username,cn=US,dc=example,dc=com where the correct Bind DN would be cn=username,ou=US,dc=example,dc=com.&lt;BR /&gt;When entering the Bind DN is very important to know exactly where in the Active Directory tree and what type of container (i.e. CN or OU) the Bind User account is located.&lt;/P&gt;&lt;P&gt;You can run a packet capture on interface ge1 and filter with ldap port 389.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;VX9000-Primary~#service pktcap on int ge 1 filter port 389&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Open the&amp;nbsp;capture in Wireshark, if there is an issue with the Bind user permissions you will see an “incorrect credentials” error message.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ovais&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 23:02:44 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-wing/wing-7-5-1-ldap-cannot-join-to-windows-active-directory-domain/m-p/86612#M8093</guid>
      <dc:creator>Ovais_Qayyum</dc:creator>
      <dc:date>2021-02-01T23:02:44Z</dc:date>
    </item>
  </channel>
</rss>

