OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Windows 2016 Active Directory
« previous next »
  • Print
Pages: [1]

Author Topic: Windows 2016 Active Directory  (Read 3362 times)

shrdlu

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Windows 2016 Active Directory
« on: December 06, 2018, 07:37:28 pm »
I looked through the forums and did not see any specific topics around this question, but in the event I missed something please feel free to just send a link and say "check this out."

I have an AD Server running on Windows 2016 and was having issues getting it to be registered with OPNsense, so before I dig in here I wanted to see if Windows 2016 AD was even supported with OPNsense for LDAP and or LDAP +OTP?

Of not, not a problem but curious if there were plans to support it, or maybe recommend some workarounds.

Thanks
Logged

bartjsmit

  • Hero Member
  • *****
  • Posts: 2023
  • Karma: 194
    • View Profile
Re: Windows 2016 Active Directory
« Reply #1 on: December 06, 2018, 09:37:53 pm »
Quote from: shrdlu on December 06, 2018, 07:37:28 pm
maybe recommend some workarounds.

RADIUS will offer AD based logins in a pretty bullet-proof way. No OTP combo though.

Bart...
Logged

shrdlu

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Re: Windows 2016 Active Directory
« Reply #2 on: December 06, 2018, 10:05:32 pm »
So, can I infer from your statement that Windows 2016 Active Directory is not supported?

Secondly, thanks for that info and I might look in that direction of using Radius.
Logged

bartjsmit

  • Hero Member
  • *****
  • Posts: 2023
  • Karma: 194
    • View Profile
Re: Windows 2016 Active Directory
« Reply #3 on: December 06, 2018, 11:07:28 pm »
AD may very well be supported, but I prefer RADIUS. From a defense-in-depth perspective a directory server is right at the heart of the network, and a firewall is at the periphery.  I think it is best to keep them separate and use strong encryption between them.

LDAP access to Windows domain controllers requires authentication, which means that your firewall holds account credentials, or you need to enable anonymous LDAP bind in AD. Neither option is attractive from a security perspective.

Bart...
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17706
  • Karma: 1618
    • View Profile
Re: Windows 2016 Active Directory
« Reply #4 on: December 07, 2018, 07:23:51 am »
To be perfectly clear: yes, AD works with all LDAP authentication options available in OPNsense given it's correctly configured.


Cheers,
Franco
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Windows 2016 Active Directory
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2