Configuring Active Directory authentication
You can add existing Active Directory users to the firewall. To do this, you add an AD server, import groups, and set the primary authentication method.
Objectives
When you complete this unit, you’ll know how to do the following:- Add and configure an Active Directory server on the firewall.
- Import AD groups using the Import group wizard.
- Set the primary authentication method so that the firewall queries the AD server first.
Add an Active Directory server
First, you add an Active Directory server that includes a search query.
- Domain name
- NetBIOS domain
- Active Directory server password
Check the properties of the Active Directory server. For example, on Microsoft Windows, go to Windows Administrative Tools.
Search queries are based on the domain name (DN). In this example, the domain name is
sophos.com
, so
the search query is: dc=sophos,dc=com
.
Import Active Directory groups
Import Active Directory groups into the firewall and specify policies for them.
Set primary authentication method
To query the Active Directory server first, you set it as the primary authentication method. When users sign in to the firewall for the first time, they are automatically added as a member of the default group specified.
Go to
and verify the imported groups.