WatchGuard® Made Simple

This site is for common setup practices as well as tips and tricks for WatchGuard® Firewall products and contain editorial content.  While every effort is made to ensure all information is correct and concise, no warranty of any kind is expressed or implied, and all information is provided on an "as is" basis.

WatchGuard® is not affiliated with this site and all trademarks and graphics referenced are the property of WatchGuard Technologies Inc. or their respective owners.  All other content is the property of Fireboxsupport.com and may not be reproduced without permission.
 

                                       PLEASE REFRESH THE  PAGES IF YOU HAVE VISITED PREVIOUSLY! - NEW CONTENT ADDED!  01/02/2007

Common Practices

Fireware Pro

Configurations and examples

Firebox SSL VPN

Firebox Core SSL VPN

Firebox X Core/Edge

Setup -

Branch Office VPN (IPSec) - Firebox/Soho

Proxy Configuration

Webblocker Configuration

Remote User configuration using MUVPN & PPTP

Spamscreen®

High Availability

Troubleshooting -

Firebox X Resetting

Rebuilding your configuration

Backing Up/Restoring your Firebox Image.

 

WatchGuard Support Programs

Top

                                                 

MoneyCentral Stock Quote
Enter (WGRD) 

 

 

Configuring your SSL VPN Firebox to authenticate to an Active Directory

 

 

In the above setup, the domain is fireboxsupport.com

 

The LDAP server is 172.25.0.155

 

The Administrator credentials are first (LDAP location, then the password.)

 

Server port is 3268

 

Administrator Bind DN is very standard and should work for everyone if you substitute your domain name.

 

CN=Administrator,CN=Users,DC=fireboxsupport,DC=com

 

Enter the Administrator password for the domain controller.

 

When the global catalog port of 3268 is used, you only need to define the Base DN where users reside.

 

In this case it is

 

CN=Users,DC=fireboxsupport,DC=com

 

No other changes need to be made.

 

 

Submit and now you need to just make a user group with the SAME name of the domain group your users will be a member of.

 

In this case the user group is “SSLVPN” on the domain controller.

 

 

 

 

 

This is all that you need, now when users login, the SSL log will say it logged them in and it sees them as a member of group  xxxx which must match your group name in the user groups section.

 

(11/11/05 15:15:23): 0:ldapd: user [scarlson] is in the following LDAP groups: SSLVPN,Administrators

 

If you see a bind error, then your authentication server information is incorrect.  Once the settings are correct and matching you will not see any bind errors in the log when you submit the settings.

 

Now you just need to ensure any user you want to allow access to is a member of this group.

 

 

Top      User Forum