Ask a questionAsk a question
 

AnswerLDAP Integration Setup

  • Monday, July 27, 2009 9:30 PMStephen Stark Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    We are trying to setup a new ISA server in our DMZ that will not be a domain member, but rather will authenticate VPN users against the domain via LDAP.  I believe we have all of the LDAP settings correct, and have verified connectivity to the domain server using LDP.exe (as well as a connectivity verifier).  However, when we go to the Groups tab in the VPN Client Properties dialouge box and try to add a new group from the domain, we are only given the choice to add groups from the local machine...as if it does not see the domain server.

    Does anyone have any setup or troubleshooting tips around this problem?

    Thanks in advance.

    Stephen
    Stephen Stark

Answers

  • Wednesday, July 29, 2009 3:27 PMDawidGK Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    Hi, Stephen
    AFAIK, you cannot use LDAP authentication for VPN (only on web listeners) on ISA Server 2006.

    Without ISA server domain membership you have to configure RADIUS (IAS) server, which can authenticate domain users.

    Dawid

All Replies