OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • cannot connect ldap ad 2008 server
« previous next »
  • Print
Pages: [1]

Author Topic: cannot connect ldap ad 2008 server  (Read 4805 times)

xkapr

  • Newbie
  • *
  • Posts: 8
  • Karma: 0
    • View Profile
cannot connect ldap ad 2008 server
« on: February 11, 2018, 01:42:49 pm »
Hi. Need help connecting to ldap.

I am trying to add new ldap server in system>access>servers.
type: ldap
hostname: ad.mydomain.cz
port: 389
transport: tcp
protocol: 3
user dn : mydomain\administrator
password: password
base dn: CN=mydomain,CN=cz
initial template: microsoft ad
authentication containers:  click select and get error message

Could not connect to the LDAP server. Please check your LDAP configuration.

When I try connect localy on ad controller ad.mydomain.cz with ldp.exe conection and browsing ldap works.

On opnsense interfaces>diagnostics>port probe:
Connection to ad.mydomain.cz 389 port [tcp/ldap] succeeded!

Connection to ldap from another computer in same network eg. linux ldap administrator works.

opnsense version. OPNsense 18.1.2_2-amd64
windows ad: windows 2008 r2 build 7601 sp1

Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: cannot connect ldap ad 2008 server
« Reply #1 on: February 11, 2018, 09:01:29 pm »
User DN must be the LDAP path, like Base DN
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

xkapr

  • Newbie
  • *
  • Posts: 8
  • Karma: 0
    • View Profile
Re: cannot connect ldap ad 2008 server
« Reply #2 on: February 12, 2018, 09:10:32 am »
Thank you for answer. So user dn must be:
CN=Administrator,CN=Users,DC=mydomain,DC=cz

I think I've already tried according to docs https://wiki.opnsense.org/manual/how-tos/user-ldap.html but I'll try again.
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: cannot connect ldap ad 2008 server
« Reply #3 on: February 12, 2018, 10:22:37 am »
Users could also be OU, you have to check with your Windows Admin
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

xkapr

  • Newbie
  • *
  • Posts: 8
  • Karma: 0
    • View Profile
Re: cannot connect ldap ad 2008 server
« Reply #4 on: February 12, 2018, 02:25:12 pm »
I tried it once again and I still can not connect. I have verified that users are CN. So

type: ldap
hostname: ad.mydomain.cz
port: 389
transport: tcp
protocol: 3
User DN: CN=Administrator,CN=Users,DC=mydomain,DC=cz
password: secret
base dn: CN=mydomain,CN=cz
initial template: microsoft ad
authentication containers: click select and get error message

Could not connect to the LDAP server. Please check your LDAP configuration.

What else can cause troubles?
Logged

bartjsmit

  • Hero Member
  • *****
  • Posts: 2023
  • Karma: 194
    • View Profile
Re: cannot connect ldap ad 2008 server
« Reply #5 on: February 12, 2018, 03:36:04 pm »
Have a look at Softerra LDAP administrator (the free Windows package) to double check your bind DN and password.

http://www.ldapadministrator.com/

Bart...
Logged

xkapr

  • Newbie
  • *
  • Posts: 8
  • Karma: 0
    • View Profile
Re: cannot connect ldap ad 2008 server
« Reply #6 on: February 12, 2018, 09:21:35 pm »
I tried to connect with ldapadministrator.com with user dn and base dn I mentioned above and connection is without troubles. Still cannot connect from opnsense.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • cannot connect ldap ad 2008 server
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2