cancel
Showing results for 
Search instead for 
Did you mean: 

Extreme Control Machine + User authentication fails

Extreme Control Machine + User authentication fails

SDR
New Contributor III


Hi,

This Topic is a a follow up to


 

Although, I hopefully configured everything as advised and discussed in above thread,   

Machine + User authentication fails. (Machine auth ONLY works fine, now!)

Below is a screenshot of  the EvaluationTool result:

 

9b635a8e5ebc40f6a8c66126253d4e30_70302b0d-5609-4778-b310-606ec3098b0f.jpg

 

I don´t see the mistake….

1 ACCEPTED SOLUTION

SDR
New Contributor III

Dear all,

today customer tested the solution/correction and it worked.

Below my solution/explanation:

In an earlier mentioned documentation (https://extremeportal.force.com/ExtrArticleDetail?an=000080814)  I primarily followed it was advised to use “cn” as Host Search Attibute (within the LDAP-configuration of “Domain users”

At least in my environment, this did not work (as shown in above screenshots). The solution was to use “dNSHostName” as Host Search Attibute (which is the default).

Changing this, the configuration worked. Machine AND User-Authentication are passed successfull.

Unfortunately, this solution is already described in https://extremeportal.force.com/ExtrArticleDetail?an=000082479 which I found during my troubleshooting.

 

In addition to this modification of the solution, I changed the advised order of the Rules.

Instead of 

  1. Authenticate and authorise a machine
  2. Authenticate and authorise a machine as a valid domain computer with a valid domain user logged in
  3. Deny a valid user who is on a non-domain (BYOD) computer

In my environment, Rule “2” never will be verified, after a Machine was successfully authenticated.

So, no user-authentication will ever happen.

For that reason, I switched the order of rule 1 and 2 and afterwards, all variations could be verified and authenticated.

 

Thanks all for your assistance.

View solution in original post

16 REPLIES 16

Miguel-Angel_RO
Valued Contributor II

SDR,

 

Your rules seems to be wrong.

The non domain machine rule is matching an AD user on a AD computer.

Could you share a screen of the rules?

Mig

StephanH
Valued Contributor III

Hello SDR,

take the user data you see in Eval Tool. Got to the corresponding LDAP Rule and select test.

Fill in the user data and check if you receive the result that you expect.

Regards Stephan
GTM-P2G8KFN