This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Having a hard time with AD server 2k8R2

I can't get it to authenticate an admin account much less join the domain.  

username is Wadmin
pass:****
Domain: ECC.local
Membergroup is Users by they are member of schema admins, enterprise admins, and domain admins.  I must be missing something simple.  Any ideas?


This thread was automatically locked due to age.
  • ok I got the thing to authenticate but it now won't join..at least not on the Astaro side.  The firewall is in the computers list in the domain it's just not being seen on the Astaro's end.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • Hi, William,

    I had that same problem when I first tried AD-SSO, and I got it to work by deleting the Astaro from the AD and letting it add itself.

    Cheers- Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I've tried that..multiple times to no avail.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • ANy ideas?  Here's the ldap string that works for the serve test:

    CN=Wadmin,CN=Users,DC=ecc,DC=local

    if i try ot use the domain admins CN anywhere in that string it fails.  when i do the authentication test it mentions i am in the users group and not admins(even though i am a member of hte admins group).  Should i cahnge my string?

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • User authentication:

    Authentication test passed.


    User is a member of the following groups:

    Active Directory Users

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • what's confusing is i can go into the prefetch area of SSO and pull up the AD tree in the webadmin.  Why is the astaro NOT seeing the fact it's joined to the domain?

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • Version 8 Specifically added support for 2008R2 Domains... you may want to try that.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • I forgot to mention I am running with windows 7 clients and in the 2k8r2 domain style.

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow

  • I forgot to mention I am running with windows 7 clients and in the 2k8r2 domain style.


    running the same setup here.  however, my astaro machine joined the domain with no trouble at all...have you tried using the NETBIOS name instead of the FQDN of your domain?

    ECC instead of ECC.local?
  • nopers but i'll try that one next..[:)]

    Owner:  Emmanuel Technology Consulting

    http://etc-md.com

    Former Sophos SG(Astaro) advocate/researcher/Silver Partner

    PfSense w/Suricata, ntopng, 

    Other addons to follow