Community discussions

MikroTik App
 
Alupis
just joined
Topic Author
Posts: 23
Joined: Wed Feb 29, 2012 6:30 pm

IPSec Users | Use ldap from Windows AD?

Wed Nov 12, 2014 9:44 pm

Is it possible to configure IPsec Users to be imported from a Windows AD?

When I view IP -> IPSec -> Users there does not seem to be any options other than to just create a local static user.

I would like to allow users or a group of users from the AD to use VPN access (so one less password/user combo to remember).
 
schmeltm
just joined
Posts: 18
Joined: Sun Jan 15, 2012 4:28 pm
Location: near Duesseldorf

Re: IPSec Users | Use ldap from Windows AD?

Thu Nov 13, 2014 2:13 pm

+1
 
User avatar
NathanA
Forum Veteran
Forum Veteran
Posts: 829
Joined: Tue Aug 03, 2004 9:01 am

Re: IPSec Users | Use ldap from Windows AD?

Thu Nov 13, 2014 3:39 pm

I don't think that RouterOS supports AAA for XAuth. What about L2TP over IPsec instead?

Regardless of whether you use L2TP over IPsec or wait for MikroTik to add support for an external XAuth user/pass database, the only source for AAA that RouterOS supports is RADIUS, not direct LDAP. So you will need to set up and configure a RADIUS server. Many RADIUS servers allow you to use LDAP as a backend data source, so as long as you use one that does, then you should be able to tie into the Windows AD LDAP database.

-- Nathan
 
User avatar
tomaskir
Trainer
Trainer
Posts: 1162
Joined: Sat Sep 24, 2011 2:32 pm
Location: Slovakia

Re: IPSec Users | Use ldap from Windows AD?

Thu Nov 13, 2014 4:20 pm

As mentioned before XAuth currently doesnt support Radius auth.

For other AAA needs against LDAP (AD DS), setup a NPS server (Windows Radius) and auth against that.
There are multiple topics on the forum about this, if you need help, post here.

Who is online

Users browsing this forum: Bing [Bot], xrlls and 60 guests