Beruflich Dokumente
Kultur Dokumente
AD Integration
2.
UnderstandingthestepsthatoccurfortheActiveDirectoryintegrationmakesiteasiertodetermine whatelementsneedtobeconfiguredandtotroubleshootwhensomethingisntworking.Hereisalistof thenecessaryphasesforAerohiveADintegration: a. APattemptstojointheActiveDirectorydomainusingSAMBA(NTLMandKerberos) i. Requiresdomainadmincredentials ii. NowtheAPresemblesanylaptopjoinedtotheADdomain.Anyvaliddomainusercanlogin usingdomainusercredentials b. ThelaptopassociatestotheAccessPoint(AP) i. SupplicantsendsanEAPoLrequest c. APencapsulatestheEAPrequestintoRADIUS i. APsendsarequesttotheFreeRADIUSmoduleembeddedintheAP d. APusesLDAPtoqueryADuserdatabase i. Requiresanyvaliddomainusercredentials e. OnceUserisdiscoveredinthedatabase,RADIUSpassestheNThashpasswordfromthesupplicant totheAD i. ADrespondswithanacceptordeny f. APgetsseedkeyfromtheFreeRADIUSservertoinitiateencryption g. Supplicantusessameseedkeytogenerateencryptioninformation
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 2 OF 14
AD Integration
b. c.
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 3 OF 14
AD Integration
e.
1. 2. 3. 4.
1. 2. 3. 4.
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 4 OF 14
AD Integration
g. 1. SelectHiveAPRADIUSServerandthenselectMoreSettings
InthedetailedAAAClientSettingsforspecifyingthelocationoftheRADIUSserver
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 5 OF 14
AD Integration
h.
IntheSSIDconfiguration
1.
NexttoRADIUSservermakesureyourHiveAPRADIUSserverobjectisselected thensavetheSSID
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 6 OF 14
AD Integration
1. Movethe802.1XssidtotheSelectSSIDProfileslistandclickApply
2.
ThensaveyourWLANpolicy
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 7 OF 14
AD Integration
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 8 OF 14
AD Integration
1. 2. 3. 4. EnteranamefortheActiveDirectoryObject SelecttheActiveDirectoryradiobutton EntertheActiveDirectoryServerIPorresolvablehostname Enteranadminusernameandpasswordforadomainadministratorthathas privilegestojoinacomputertothedomainsothattheAPcanadditselftothe domain. NOTE:Theadminusernameandpasswordarenotrequiredtobeenteredin HiveManager.Ifyouprefer,youcanleavethissectionblank,finishtherestof thisdoc,andgototheCLIandtypeexecaaanetjoinprimaryusername <domainadminusername>password<domainadminpassword>tojointheAP tothedomain ComputerOU:OnlyrequiredifyouwanttheAPtojoinanOUotherthan Computers NOTE:Thestringcanbeupto256charactersandmustbeinthefollowing format:ou\subou\subou.Ifthereareanyspaces,enclosetheentirestringin quotationmarks.Youcanuseeitherforwardslashesorbackslashesbetween directorynamesinthecomputerou. Domain:EnterthenameoftheDomain(ex:AEROHIVE) FullName:FQDNoftheDomain(ex:aerohive.com)
5.
6. 7.
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 9 OF 14
AD Integration
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 10 OF 14
AD Integration
m. IntheHiveAPAAAServerSettings
1. 2. 3.
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 11 OF 14
AD Integration
2.
3. 4.
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 12 OF 14
AD Integration
p.
ClickSave SelectalltheHiveAPsthatwillbeusingthe802.1XSSIDwithActiveDirectoryandclickmodify
2.
q.
1. ClickNextwhenpromptedtouploadthecertificates
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 13 OF 14
AD Integration
2.
EvenifyouhaveuploadedconfigstothisAPbefore,performaCompleteupload. ThecertificatechangesandtheADjoinworkbetterafterareboot.
r.
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.
PAGE 14 OF 14
AD Integration
4.
ConfirmtheAPhasjoinedthedomain NOTE:Youmayhavetorightclickonthecomputerswindowpaneandclickrefresh s. Testthe802.1XSSID Troubleshooting a. IftheAPcannotjointhedomain,checktomakesuretheWORKGROUP(Domain)andDOMAIN(Full NameorFQDN)arecorrect. i. Fromtheconsole,testtoseeyoucanmanuallyjointheAPtothedomain 1. Execaaanetjoinprimaryusername<domainadmin>password<adminpassword> ii. Resultingerrormessagesoftenexplaintheissue b. IftheAPhasjoinedtothedomain,butusersarenotauthenticating,itispossibletotestuser authenticationfromtheAPtotaketheclientoutoftheequation i. Execaaantlmauthusername<domainuser>password<userpassword> ii. Resultingerrormessageexplainstheissue c. IftheAPhasjoinedthedomainandsomeuserswork,therearedebugcommandstoseewhatelseis goingon i. _debugradiuscomm ii. _debugradiusexcessive iii. _debugradiusverbose iv. debugconsole d. Iftheabovecommandsdonotwork,trydebuggingauthentication i. _debugauthall
2.
2007-2010 Aerohive Networks Inc. All Rights Reserved For Aerohive internal use only.