Forum Discussion
Chatan_Mistry_1
Nimbostratus
Jan 10, 2007FirePass 4100 with multple AD authorisation
Hi!
I am stuck! I currently have a clustered FirePass environment using v5.5. We use RSA authentication, with AD authorisation against a single domain - we use the AD groups to identify waht resources the user has access to.
However, we want to expand the solution to cover multiple AD domains (in multiple forests). I know thaty v6 support fallback master groups, but I don't think this will work as the time required to cycle through the fallback groups would result in the RSA passcode timing out.
Does anyone have any suggestions on how to approach this? (please?!)
Chatan
- Matt_60535
Nimbostratus
I'm in the same boat. I have a failover FirePass environment using v5.5 but about to upgrade to 6.0. Our environment has multiple AD domains and we have a requirement to use dynamic mapping of resource groups that cover those multiple AD domains. Is there any way to dynamically map resource groups to multiple AD domains? If not, is FirePass coming out with a version that supports this in the future? - Fuzz_31058
Nimbostratus
I think you are correct that this is not a supported configuration today. You should contact Support and open a CR (Change Request). The more people that call in and have a ticket tied to the CR the more likely it is to get implemented. You can also engage your local sales team to help drive the CR. - Fuzz_31058
Nimbostratus
Just another thought, If you only have two AD domains you could possibly create a second Master group with NTLM instead of AD and then use that for the dynamic resource group mapping. If you have more then 2 domains you will need to open the CR. - psilvas
Altostratus
You are correct. Currently AD forests are not supported but we are working to add this in the next feature (6.02) release. - Matt_60535
Nimbostratus
Thanks guys. I appreciate the help. - Melvin_Tan_6033
Nimbostratus
Dear all,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects