Shunze ¾Ç¶é >¸ê°T³]³Æ±M°Ï >Extreme & Enterasys > ¡m¤À¨É¡nNAC³z¹LLDAP¶i¦æ±b/±KÅçÃÒ «¢Åo¡AÁÙ¨S¦³µù¥U©ÎªÌµn¤J¡C½Ð§A[µù¥U|µn¤J]
« ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD » Åã¥Ü¦¨¦C¦L¼Ò¦¡ | ¼W¥[¨ì§Úªº³Ì·R
µoªí·s¥DÃD µoªí¦^ÂÐ
§@ªÌ
¥DÃD
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡nNAC³z¹LLDAP¶i¦æ±b/±KÅçÃҤޥΦ^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

NAC°£¤F¯à³z¹L Local Password Repository »P¥~³¡ Radius server ¨âºØ¤è¦¡¨ÓÃÒÅç¨Ï¥ÎªÌ¥~¡A
ÁÙ¥i¥H³z¹L LDAP ¨ó©w¨ÓÅçÃҨϥΪ̱b±K¡A
·íµM³o LDAP ¤]¤ä´©¤F·L³nActive Directory¡C

­nÅýNAC¯à³z¹L LADP »P·L³nAD¨Ó¶i¦æ¨Ï¥ÎªÌÃÒÅç¡AADºô°ìªº¨t²ÎºÞ²z­û±b/±K¬O¥²³Æªº¡C
NAC¦b³z¹L LDAP ¶i¦æ¨Ï¥ÎªÌ±b/±KÅçÃҮɡA·|°e¥X ntlm_auth µ¹ADªºdomain controller¡A
µM«á¥H LDAP ²ÕºA¤¤ªººô°ì¨t²ÎºÞ²z­û±b/±K join ºô°ì¡C
©Ò¥H³o²Õ±b¸¹¥²»Ý¬ODomain Administrator group¤¤ªº¦¨­û¡F
§_«h·|¦b¥[¤Jºô°ì®É¥¢±Ñ¡AµLªkÅçÃҨϥΪ̡C

¦¹¥~¡AÁÙ­n§âNACªºDNS«ü¦VAD¡A³o¼ËADºô°ìªºFQDN¤~¯à¥¿½T¸ÑªR¡C


¥H¤U§Ú­Ì¥HWindows 2008 R2«Ø¥ßªºADºô°ì demo.com.tw °µ¥Ü½d¡A
¾Þ§@NAC³z¹LLDAP¶i¦æADºô°ìªº±b/±KÅçÃÒ¡C

  1. ©óNAC Manager¤¤¡A¿ï¦nNAC Appliacne«á¡AÂIÀ» Default ³]©wNAC Configuration¡C


    ¨Ó¨ìAAA«á¡A·s¼W¤@­ÓAAA Configuration - LDAPAuthen¡A
    ¤Ä¿ï Authenticate Requests Locally for MAC (All)¡A
    ¦b¤U©Ôªº Local Password Repository ¤¤¡A¿ï None ¤£¹L³z¹L Local Password Repository ¶i¦æ±b/±KÅçÃÒ¡A
    µM«áÂI¶}¹w³] Authentication Mapping¡A©Î·s«Ø¤@µ§¡C


    ¦]¬°§Ú­Ì¬O­n³z¹L LDAP ÅçÃÒ¡A©Ò¥H¦bAuthentication MethodùØ¡A§Ú­Ì¿ï¾Ü LDAP Authentication¡C

    ¿ï§¹«á¡A¥¦·|¦Û°Ê±a¥X LDAP Authentication Type »P Supported RADIUS Type ªº­È¡C

    ±µµÛ¦b LDAP Configuration ùØ¡A¿ï¾Ü New ¡A§Ú­Ì¨Ó«Ø¥ß¤@µ§ LDAP ²ÕºA¡C


    «ö¤U Add «ö¶s¡A¿é¤J LDAP ªºserver IP¡C

    ª`·N³q°T¨ó©w¬O ldap¡Aport¬O389¡C

    µM«á¦b Authentication Settings °Ï¶¡ùØ¡A¿é¤JADºô°ìªº¨t²ÎºÞ²z­û±b/±K¡F
    ¦b Search Settings °Ï¶¡ùØ¡A¿é¤JUser/Host/OUªºSearch Root¸ê°T¡C

    ³Ì«á¦b³Ì¤U­±¦b OU Object Classes ªº¿é¤J®Ø®Ç¡A«ö¤U¤p¤pªº¤U©Ô«ö¶s¡A
    ¿ï¾Ü Poulate Active Directory: User Default¡C

    ¿ï¦n«á¡A¥¦·|¦Û¤v±a¥X Schema Definition ªº¬Û¹ï¸ê°T¡A¤£»Ý¤â°Ê³v¤@¿é¤J¡C


    ±µµÛ¥i¥H³z¹L Test «ö¶s¡A¨Ó´ú¸Õ LDAP ªº³]©w¬O§_¥¿½T¡A
    ºô°ì¤¤ªº¨Ï¥ÎªÌ±b¸¹¯à§_¶¶§Q¬d§ä¨ì¡C






    ³s½u½T»{µL»~«á¡A«ö¤UOK¡ALDAPªºAuthentication³]©w´N§¹¦¨¤F¡ã


  2. ¨Ó¨ìRules¡A³]©wLDAPÅçÃҤ覡³q¹L«á©Ò¹ïÀ³ªºÅv­­¡C
    «ö¤U ¡§·s¼W¡¨ ¹Ï¥Ü¡A¨Ó«Ø¥ß¤@µ§·s³W«h¡C


    User Group´N¿ï New¡A§Ú­Ì­n¨Ó«Ø¤@µ§ User Group ¹ïÀ³ LDAP »{ÃÒ¹Lªº±b¸¹¡C


    «ö¤U¾¦½ü¹Ï¥Ü¡A¿ï¾Ü LDAP OU Inport ¨Ó¶×¤J¤w«Ø¥ßªºLDAP²ÕºA¡C




    LDAP²ÕºA¶×¤J«á¡A¨Ì¹ê»Ú»Ý¨D¨Ó§R´î±ø¥ó¡C

    ¥H¥»¨Ò¨Ó»¡¡A§Ú­Ì¬O°µ¼eÃPªº¿z¿ï¡F
    ¥u­n²Å¦X¥ô¦ó¤@µ§(Match Any)¡A´N²Å¦X¦¹ User Group ±ø¥ó¡C

    µM«áµ¹³o User Group ¤@­Ó¹ïÀ³ªº Profile ¨Ó®M¥Î¨äºô¸ôÅv­­¡A
    ­n¨D«eºÝ Switch ÅçÃҫ᪺ port ­n®M¥Î¦¹ Profile ¹ïÀ³ªºÅv­­¡C


    ¦^¨ìNAC Manager­º­¶¡A«ö¤U Enforce ¹Ï¥Ü¼g¤J§ó·s¡ARadiusªºÅçÃÒ³]©w´N§¹¦¨¤F¡C




µn¤JÅçÃÒ
«eºÝ¹q¸£±Ò¥Î802.1X«á¡A¶i¦æµn¤JÅçÃÒ¡C

¦¨¥\µn¤J«á¡A§Ú­Ì¥i¦bNAC Managerªº End-Systems Æ[¹î¨Ï¥ÎªÌªºµn¤J¸ê°T¡C


­è¤~ªºµn¤J¡A¬O¥Ñ±b¸¹ root ¦b ge.1.2 ¥H 802.1X ªºÅçÃÒÃþ«¬¡A³z¹LLDAPªºÅçÃÒ¾÷¨î¨Óµn¤J¡C
µn¤J«áªºProfile¬O Default NAC Profice¡A²Å¦X§Ú­Ìªº¹w´Á¡A´ú¸Õ¦¨¥\¡C



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2014-08-23, 08:47 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
shunze
¤u¤Í§B§B


µù¥U¤é´Á: 2002 04
¨Ó¦Û: ¼é¦Á²×¤î¤§¦a
¤å³¹: 2380

shunze Â÷½u
¡m¤À¨É¡nRejected NTLM Authentication¤Þ¥Î¦^ÂÐ ½s¿è/§R°£¤å³¹ ·j´M¥Ñ  µoªíªº¨ä¥L¤å³¹ ¦^³øµ¹ª©¥D IP ¦ì¸m ¦^¦¹­¶³Ì¤W¤è

¶¶¤l¤@¶}©l¦b´ú¸ÕNAC³z¹LLDAPÅçÃҮɡA¹J¨ì«Ü¤F¤jªº®À§é¡C

©ú©ú¦bLDAPªº³s½u´ú¸Õ³£«Ü¶¶§Q¡A
¤]¯à°÷¦¨¥\ªº§ì¨ìºô°ì¨Ï¥ÎªÌ±b¸¹¡C
¦ý¹ê»Ú³z¹L802.1X³s¤WNACÅçÃҮɡA³£¥X²{ Rejected NTLM Authentication ªº¿ù»~¡C


The authentication request was rejected dueto NTLM authentication error: Reading winbind reply failed! (0xc0000001)




¦b¥dÃö¥d¤F¤@¨â¤Ñ«á¡A±o¨ì¦P¨Æªº±j¤OÀ°§U¡C

³z¹LNACªº WebView ¨ÓÀ˵ø Server Log °T®§®É¡A




µo²{NAC¦bjoin domain®É¡A®Ú¥»´N¸ÑªR¨ì¿ù»~ªººô°ìIP¡I

2014-08-22 16:15:15,465 ERROR [SambaInstallationManager] Failed to join domain: "DEMO.COM.TW" for user: "administrator" with error code: 1
ADS join did not work, falling back to RPC...
Could not connect to server AD
The username or password was not correct.
Connection failed: NT_STATUS_LOGON_FAILURE
Failed to join domain: failed to lookup DC info for domain 'DEMO' over rpc: Logon failure
2014-08-22 16:15:15,559 ERROR [SambaInstallationManager] Looked up IP "DEMO.COM.TW" => DEMO.COM.TW/210.200.66.80, but was not able to contact it via ping.
2014-08-22 16:15:15,626 ERROR [SambaInstallationManager] The user: "demo\administrator" and password were verified via LDAP and we verified the user is a domain admin.
2014-08-22 16:15:15,627 INFO [NACInfoLogger] Re-starting winbindd deamon due to updated configs - enforce...
2014-08-22 16:22:36,858 INFO [NACInfoLogger] Enforce update command received


´ú¸Õªººô°ìdemo.com.tw¡A¨äIPÀ³¸Ó¬O¤º³¡µêÀÀIP 192.168.30.21¡F
¦ýNAC«o¸ÑªR¨ì¤F¥~³¡¯u¹êºô°ìªº¹êÅéIP 210.200.66.80¡I
«Ü©úÅ㪺¡A¬ONAC¤WªºDNS¨Ã¨S¦³«ü¦V´ú¸Õºô°ìdemo.com.twªºAD¥D¾÷¡C

¤£¹L¦b¤@¶}©l¶i¦æ´ú¸Õ®É¡A¶¶¤l©ú©ú´N¦³¦bNACªº³]©wÀÉ /usr/postinstall/network.properties ùحקï¤F NACNAMESERVER¡A
Åý¥¦¹ïÀ³¨ì´ú¸Õºô°ìdemo.com.twªºAD¥D¾÷192.168.30.21¡A
¦Ó¥B©È¥¦¨S¦³¥Í®Ä¡A§ÚÁÙ¶i¦æ¤F­«¶}¾÷¡C
©~µMÁÙ¬O¨S¦³µo¥Í®ÄªG...

³Ì«á¦P¨Æ«Øij³z¹LNACªº³]©w¤u¨ã nacconfig ¨Ó­«·s³]©w¡C
/usr/postinstall/./nacconfig


µ²ªG¡A
LDAPÅçÃÒ´N¹L¤F...

¹j¦æ¦p¹j¤s¡A
°ª¤âªGµM¤£¬O®ö±oµê¦W¡I



♥¶¶¤l¦Ñ±Cªººô©ç¡A½Ð¦hÃö·Ó¡ã

If you don't like something, change it.
If you can't change it, change your attitude.
Don't complain!




2014-08-23, 10:58 shunze ªº­Ó¤H¸ê®Æ §â shunze ¥[¤J¦n¤Í¦Cªí µo°eEmailµ¹ shunze ÂsÄý shunze ªººô¯¸ MSN : shunze@gmail.com
  « ¤W¤@½g¥DÃD ¤U¤@½g¥DÃD »
µoªí·s¥DÃD µoªí¦^ÂÐ
¸õ¨ì:

Powered by: Burning Board 1.1.1 2001 WoltLab GbR