ASG Firmware Version: 7.305
We have successfully setup LDAP binding and the test server and test authentication works fine.
We have turned on the option to "Create Users Automatically", and set the options for it to create user objects for End-User Portal and SSL VPN, but for LDAP this does not appear to be working at all. It DOES work for Tacacs+, however.
(looking at the logs, it doesn't appear to be even querying the LDAP when the "unknown" user tries to login to user portal).
Oddly enough when we first installed the system, it worked for ONE and ONLY ONE test user, but hasn't worked for any other user since.
Is there a known bug here, or are we missing something?
In the back-end authentication preference order, we have LDAP first and Tacacs+ farther down the list. (Not all users are in Tacacs...)
If we create the user manually, and set it to synchronise with a backend authentication method, the user can login to the portal, but since this authentication is fixed to remote, they cannot change their ASG password, and cannot use PPTP or L2TP/IPsec VPNs as they require local authentication for PPPD.
Ideally, we want the user creation to intially be from "unknown" user authenticated by LDAP which then creates the local user objects. The next time the user logs into the portal, he then has the ability to change his LOCAL password. (This was the case with the first test user, and worked fine.. but no further users can be added this way).
Any assistance would be appreciated.
Thanks,
L.
This thread was automatically locked due to age.