Re: [j-nsp] SRX100 LDAP

2014-03-25 Thread Шепелев Андрей
b22915a388a3399b23d0d982da7a.jpg > http://screenshot.su/show.php?img=1748986a1a7aab2e7df5c0bea903b1ac.jpg > > =(( > > > 2014-03-21 13:54 GMT+06:00 Bikram Singh : > > >> >> >> >> >> > From: sbik...@live.com >> > To: xamalon...@gmail.com >>

Re: [j-nsp] SRX100 LDAP

2014-03-25 Thread Шепелев Андрей
3:14:31 +0530 > > CC: juniper-nsp@puck.nether.net > > Subject: Re: [j-nsp] SRX100 LDAP > > > > > > > > > > tried everything nothing helps... i`m begining to think that i have > broken srx =)) or something like that. it did not want even trying to

Re: [j-nsp] SRX100 LDAP

2014-03-21 Thread Bikram Singh
> From: sbik...@live.com > To: xamalon...@gmail.com > Date: Fri, 21 Mar 2014 13:14:31 +0530 > CC: juniper-nsp@puck.nether.net > Subject: Re: [j-nsp] SRX100 LDAP > > > > > tried everything nothing helps... i`m begining to think that i have broken > > sr

Re: [j-nsp] SRX100 LDAP

2014-03-21 Thread Bikram Singh
> tried everything nothing helps... i`m begining to think that i have broken > srx =)) or something like that. it did not want even trying to athorize the > users very strange access {á á profile TPAD {á á á á authentication-order ldap;á á á á ldap-options {á á á á á á base-distinguished

Re: [j-nsp] SRX100 LDAP

2014-03-20 Thread Per Westerlund
You did not set up separate address for authentication like below, try that first. /Per Sent from my iPad, please ignore stupid spelling corrections! > 21 mar 2014 kl. 04:54 skrev Шепелев Андрей : > > show interfaces ge-0/0/1 > unit 0 { > family inet { > address 192.168.203.200/2

Re: [j-nsp] SRX100 LDAP

2014-03-20 Thread Шепелев Андрей
tried everything nothing helps... i`m begining to think that i have broken srx =)) or something like that. it did not want even trying to athorize the users very strange version 11.2R4.3; system { host-name test-srx100.adm.n.tp.ru; root-authentication { encrypted-password "$1$

Re: [j-nsp] SRX100 LDAP

2014-03-19 Thread Bikram Singh
> set access ldap-options base-distinguished-name DC=tp,DC=ru > set access ldap-options search search-filter sAMAccountName= > set access ldap-options search admin-search distinguished-name > cn=junos,dc=tp,dc=ru > set access ldap-options search admin-search password > "$9$k.TFtu1RcyAtWLX7VbfTQ3

Re: [j-nsp] SRX100 LDAP

2014-03-19 Thread Per Westerlund
I was a but quick, the configuration under [edit access] is not the same on EX and SRX (of the versions I have). Here is a working setup, although I am using RADIUS instead of LDAP. As long as you get the server details correct, that should not matter; they are both external authentication serv

Re: [j-nsp] SRX100 LDAP

2014-03-19 Thread Ben Dale
It's been a long time since I've played with this, but it's not something simple like: set access-profile TPAD is it? The Junos doco doesn't mention it, but for some applications you need to specifically activate the access-profile. On 18 Mar 2014, at 8:54 pm, Шепелев Андрей wrote: > Hi Al

Re: [j-nsp] SRX100 LDAP

2014-03-19 Thread Per Westerlund
I might have been a bit hasty, thinking more of the way RADIUS is usually set up. I will try to set something up later today (if time permits), I am anyway labbing with dot1x and MAC RADIUS right now, it is somewhat similar. /Per 19 mar 2014 kl. 03:44 skrev Шепелев Андрей : > changed: > > set

Re: [j-nsp] SRX100 LDAP

2014-03-18 Thread Шепелев Андрей
changed: set access ldap-options base-distinguished-name DC=tp,DC=ru set access ldap-options search search-filter sAMAccountName= set access ldap-options search admin-search distinguished-name cn=junos,dc=tp,dc=ru set access ldap-options search admin-search password "$9$k.TFtu1RcyAtWLX7VbfTQ3Ap" s

Re: [j-nsp] SRX100 LDAP

2014-03-18 Thread Per Westerlund
I haven’t done it myself (yet), but you probably need to define the ldap-server directly under the stanza ”access”. In your profile TPAD you just reference the ldap server with address 10.60.0.5, but you have not defined it. When you define it, you can also specify what destination port and sour

[j-nsp] SRX100 LDAP

2014-03-18 Thread Шепелев Андрей
Hi All ! I`m trying to made a web portal auth with LDAP integration on SRX 100. Here is the config: ## Last changed: 2014-03-11 05:44:05 UTC version 11.2R4.3; system { host-name test-srx100.adm.n.tp.ru; root-authentication { encrypted-password "$1$yo2A3wox$K/.Epl658XW1r4Z9BgDWm0"