cancel
Showing results for 
Search instead for 
Did you mean: 

NAC Manager LDAP Integration with Sub Domain

NAC Manager LDAP Integration with Sub Domain

info_systemhaus
New Contributor II
We are using NAC Manager with policys to authentificate our Staff which ist coming wireless from a EWC ...

The Authentification works with LDAP against the Domain. .... username\Domain

Example : Hans.Mustermann@thhf.net

Now we want to integrate also the students from our School into this ldap authentification,

but they are located into an subdomain.

Example : Franz.Mustermann@stud.thhf.net

Does this work with Nac Manger from Extreme ?? , we are using Netsight / NAC Manager 6.1.0

The Nac Manager know the ldap Connection to the Primary Domain and is joined into this Domain, rather a Student send a logon request with his subdomain logon, the ldap should forward this to the subdomain DC ... i think this is more a Windows Problem.

I only want to know if here is anybody who has already a working Environment with subdomains and LDAP Authentification.

Regards

Christian

PS : Sorry for bad gramma .. non native english author

11 REPLIES 11

Hi Christian,

I think the "Should work" of Pala goes more in the direction that you can't be 100% sure in IT 😉

I deployed NAC in multi domain scenarios and you there you have different kind of deployments.

If you are able to join the NAC into the different domains - all is fine. Eg. myDomain.comand stud.mydomain.com. But you need 2 LDAP Configurations. NAC gets Domain member of both domains.

If you don't have the priveledge for the 2nd domain you've got a pretty good chance to fail even if the 2 domains have a full trust. In this scenario I would set up a pair of Windows NPS servers and use NAC for that domains as a radius proxy.

Regards
Michael

Many THX ... but should work is not enough.... 

I want to find someone who has a working NAC Manager LDAP Integration with Sub Domains

As you write .. different LDAP Server Settings .. should not work, because as far as i know .. the Nac Manager LDAP join the Domain and Need every time the connect to the Primary Domain ....

GTM-P2G8KFN