Hello Steve,

the better way to debug that is to use ldapsearch or adsiedit.msc to
check the exact attributes of the user (memberof) and do the good rule.

Regards
Fabrice


Le 2015-02-13 07:08, Steve Allen a écrit :
> Hi
>
> I have been testing AD integration with PF and so far I can
> authenticate a user and if they are a member of the IT Support
> security group they go into the IT-VLAN.
>
> If I test a user account against a rule that states if you are a
> member of "Domain Users" you go into Corporate VLAN it doesn't seem to
> work and it sends me the error of "maximum number of devices". The
> logs show it does not match a rule.
>
> Now if I create a new security group called Corporate Users and add
> the user to that group. Then update the rule to say if your in the
> Corporate Users security group you go into the Corporate VLAN it works
> fine.
>
> Is this a known problem that the default user groups in AD don't seem
> to work in the rules for AD sources?
>
> Kind regards,
>
> Steve
>
>
> -- 
> Regards,
>
> Steve Allen
>
>
>
>
>
> ------------------------------------------------------------------------------
> Dive into the World of Parallel Programming. The Go Parallel Website,
> sponsored by Intel and developed in partnership with Slashdot Media, is your
> hub for all things parallel software development, from weekly thought
> leadership blogs to news, videos, case studies, tutorials and more. Take a
> look and join the conversation now. http://goparallel.sourceforge.net/
>
>
> _______________________________________________
> PacketFence-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/packetfence-users


-- 
Fabrice Durand
[email protected] ::  +1.514.447.4918 (x135) ::  www.inverse.ca
Inverse inc. :: Leaders behind SOGo (http://www.sogo.nu) and PacketFence 
(http://packetfence.org) 

Attachment: 0xF78F957E.asc
Description: application/pgp-keys

------------------------------------------------------------------------------
Dive into the World of Parallel Programming. The Go Parallel Website,
sponsored by Intel and developed in partnership with Slashdot Media, is your
hub for all things parallel software development, from weekly thought
leadership blogs to news, videos, case studies, tutorials and more. Take a
look and join the conversation now. http://goparallel.sourceforge.net/
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to