Articles Articles Most Popular Articles Most Popular Articles Most Helpful Articles Most Helpful Articles
DrillDown Icon Table of Contents Back
 . . . . . . . . . . . . .
DrillDown Icon What's New
DrillDown Icon Knowledge Base Information
DrillDown Icon Cyberoam UTM
DrillDown Icon Product Literature
DrillDown Icon Best Practices & Policies
DrillDown Icon Protect Your Cyberoam Appliances from Power Fluctuations
DrillDown Icon Version 10.x
DrillDown Icon Cyberoam Maintenance
DrillDown Icon FAQ's
DrillDown Icon How To
DrillDown Icon Anti Spam
DrillDown Icon Anti Virus
DrillDown Icon Authentication
DrillDown Icon Configure Guest User Authentication
DrillDown Icon Configure Windows Server 2008 as a RADIUS Server with MS-CHAP v2 Authentication
DrillDown Icon Push NTLM Settings in Internet Explorer Through GPO in Windows Server 2008
DrillDown Icon Install Novell eDirectory Compatible CTAS
DrillDown Icon Integrate Cyberoam with RSA SecurID as a RADIUS Client
DrillDown Icon Allow Specific Websites without Authentication
DrillDown Icon Configure NTLM Support in Web Browsers
DrillDown Icon Configure NTLM in Cyberoam
DrillDown Icon Configure Cyberoam to use RADIUS Server for Authentication
DrillDown Icon Customize a Denied Message on Cyberoam Appliance
DrillDown Icon Integrate Cyberoam with LDAP
DrillDown Icon Serve a Denied page instead of Captive Portal for unauthenticated users
DrillDown Icon Implement Clientless SSO Authentication in Multiple Active Directory Domain Controller
DrillDown Icon Assign Group Membership to Users in case of Tight Integration with Active Directory
DrillDown Icon Integrate with Active Directory
DrillDown Icon Implement Clientless SSO Authentication in Single AD Domain Controller Environment
DrillDown Icon Implement SSO Authentication with AD
DrillDown Icon Import AD Groups
DrillDown Icon Implement Single Sign on Authentication with Active Directory Integration with Non-English version of Windows
DrillDown Icon Serve a Denied Page with Captive Portal Link for Unauthenticated Users
DrillDown Icon Clients
DrillDown Icon Content Filtering
DrillDown Icon Firewall
DrillDown Icon Identity-based Policies
DrillDown Icon IPS
DrillDown Icon Logs & Reports
DrillDown Icon Multiple Gateway - Load Balancing and Failover
DrillDown Icon Quality of Service (QoS)
DrillDown Icon Registration
DrillDown Icon Routing
DrillDown Icon SSL VPN
DrillDown Icon System
DrillDown Icon Users and Groups
DrillDown Icon Virtual LANs
DrillDown Icon VPN
DrillDown Icon Web Application Firewall (WAF)
DrillDown Icon Wireless LAN
DrillDown Icon Configure Wireless WAN
DrillDown Icon TroubleShooting
DrillDown Icon Version 9.x
DrillDown Icon Visio Stencils
DrillDown Icon Glossary
DrillDown Icon Product Technical Support
DrillDown Icon Compatibility
DrillDown Icon Cyberoam Virtual UTM
DrillDown Icon Endpoint Data Protection
DrillDown Icon Cyberoam SSL VPN
DrillDown Icon Cyberoam iView
DrillDown Icon Cyberoam Central Console
DrillDown Icon Cyberoam's On-Cloud Management Service
  Email This ArticlePrintPrint Current Article and All Sub-Articles
Rate Icon Rate Icon Rate Icon Rate Icon Rate Icon
 
Import Active Directory Groups
 
Applicable to Version : 10
 
This article describes how to import Active Directory groups for the purpose of authentication and define policies.
 
Prerequisites:
 
   ·  Active Directory server configured in Cyberoam.
 
     Refer How To – Implement Single Sign On Authentication with Active Directory, if you have already not integrated AD server and cyberoam.
 

Step 1.
 Import AD group
 
Once you have configured and added AD details select Identity --> Authentication -->Authentication Server and click Import Group(s) link against the AD server from which you want to import AD groups.
 
 
 

 
 
Follow the on-screen steps:
 
Step 2: Specify Base DN. Cyberoam will fetch AD groups from the specified Base DN.
 
To import users from default AD Container:
  
 
Note: - String for Base DN* - cn=user, dc=Cyberoam, dc=local
 
To import users from custom AD Container:
 
 
Note: - String for Base DN* - ou=Internet Groups, dc=Cyberoam, dc=local
 
If multiple custom containers are created, repeat the entire process for each container.
 
Step 3: Select Groups that are to be imported in Cyberoam. Use <Ctrl> + Click to select multiple groups. All the groups (not imported and already imported groups in Cyberoam) created in AD are displayed. * besides the group name indicates that the group is already imported to Cyberoam.

Use arrows to move groups across the group lists.
 
 

Step 4: Select various policies (Surfing Quota, Access time, Bandwidth, Internet Access and Data transfer) and user authentication time out to be applied on the group members.

By default, “Attach to all the Groups” is enabled, hence Cyberoam will attach same policies to all the imported Groups i.e. common policies across the imported groups.

Do not enable “Attach to all the Groups” for the policy if you want to specify:

   · different policy for all the groups

   · specific policy to all the groups

   · specific policy to a specific group

For example if you want to specify different Internet Access policy to different groups, do not enable “Attach to all the Groups”.
 
 
 
Step 5: If you have disabled “Attach to all the Groups”, specify policies to be applied to each group   
 
Once you close the Wizard, Manage Groups page will be opened. All the imported groups are appended at the end of the list. All the imported groups are appended at the end of the list on the Manage Group page.
 
 

If user is the member of multiple AD groups, Cyberoam will decide the user group based on the order of the groups defined in Cyberoam. Cyberoam searches Group ordered list from top to bottom to determine the user group membership. The first group that matches is considered as the group of the user and that group policies are applied to the user.

Re-ordering of groups to change the membership preference is possible using Wizard.
 
                                                                                                                                                                                                                                 
                                                                                                                                                                                       Document Version: 1.0-05/05/2010
Attachments
Related Articles

Article ID: 1627