Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
Windows 2016 Active Directory
« previous
next »
Print
Pages: [
1
]
Author
Topic: Windows 2016 Active Directory (Read 3345 times)
shrdlu
Newbie
Posts: 5
Karma: 0
Windows 2016 Active Directory
«
on:
December 06, 2018, 07:37:28 pm »
I looked through the forums and did not see any specific topics around this question, but in the event I missed something please feel free to just send a link and say "check this out."
I have an AD Server running on Windows 2016 and was having issues getting it to be registered with OPNsense, so before I dig in here I wanted to see if Windows 2016 AD was even supported with OPNsense for LDAP and or LDAP +OTP?
Of not, not a problem but curious if there were plans to support it, or maybe recommend some workarounds.
Thanks
Logged
bartjsmit
Hero Member
Posts: 2018
Karma: 194
Re: Windows 2016 Active Directory
«
Reply #1 on:
December 06, 2018, 09:37:53 pm »
Quote from: shrdlu on December 06, 2018, 07:37:28 pm
maybe recommend some workarounds.
RADIUS will offer AD based logins in a pretty bullet-proof way. No OTP combo though.
Bart...
Logged
shrdlu
Newbie
Posts: 5
Karma: 0
Re: Windows 2016 Active Directory
«
Reply #2 on:
December 06, 2018, 10:05:32 pm »
So, can I infer from your statement that Windows 2016 Active Directory is not supported?
Secondly, thanks for that info and I might look in that direction of using Radius.
Logged
bartjsmit
Hero Member
Posts: 2018
Karma: 194
Re: Windows 2016 Active Directory
«
Reply #3 on:
December 06, 2018, 11:07:28 pm »
AD may very well be supported, but I prefer RADIUS. From a defense-in-depth perspective a directory server is right at the heart of the network, and a firewall is at the periphery. I think it is best to keep them separate and use strong encryption between them.
LDAP access to Windows domain controllers requires authentication, which means that your firewall holds account credentials, or you need to enable anonymous LDAP bind in AD. Neither option is attractive from a security perspective.
Bart...
Logged
franco
Administrator
Hero Member
Posts: 17668
Karma: 1611
Re: Windows 2016 Active Directory
«
Reply #4 on:
December 07, 2018, 07:23:51 am »
To be perfectly clear: yes, AD works with all LDAP authentication options available in OPNsense given it's correctly configured.
Cheers,
Franco
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
Windows 2016 Active Directory