<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic vsz ldap group access in SmartZone and Virtual SmartZone</title>
    <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vsz-ldap-group-access/m-p/28949#M1991</link>
    <description>I'm trying to get a remote virtual smartzone to connect to AD via ldap. The AD server has a port forward from the firewall, the VSZ is also behind a firewall with all port forwards working. I have SSIDs working with WPA2 personal fine.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I've got device auth working via radius from the APs but the replaced ZD was using a portal to let BYOD devices into the building. To allow https web portal I am trying to configure the controller for guest access rather than the APs.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I have the VSZ talking to the AD via ldap and I can type a wrong username in and it fails, I can type a correct user and it lets me in. So I look it one step further and try and get it to work with AD groups. Using the article&amp;nbsp;&lt;A alt="" href="https://support.ruckuswireless.com/articles/000010448" rel="nofollow" target="" title="Link httpssupportruckuswirelesscomarticles000010448" type="" value=""&gt;https://support.ruckuswireless.com/articles/000010448&lt;/A&gt; is put the required group into the search filter:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;eg&amp;nbsp;(objectClass=*)(memberof=CN=BYOD,CN=Users,DC=example,DC=local)&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Regardless of if the user is in the group or not the SZ authenticates the user and lets them on.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Also, annoyingly the search filter input box is limited on the number of characters, the real group name I want to use is:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;CN=Wireless - BYOD Users,OU=Wireless Configuration,DC=example,DC=local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I was hoping maybe I could use the guid for the search filter to solve the number of characters issue.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;A side issues is that the AAA Test doesn't work, the screen greys and the waiting star spins but nothing comes back.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Any suggestions would be appreciated.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Tim&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
    <pubDate>Mon, 03 Aug 2020 17:34:50 GMT</pubDate>
    <dc:creator>tim_guy_6698086</dc:creator>
    <dc:date>2020-08-03T17:34:50Z</dc:date>
    <item>
      <title>vsz ldap group access</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vsz-ldap-group-access/m-p/28949#M1991</link>
      <description>I'm trying to get a remote virtual smartzone to connect to AD via ldap. The AD server has a port forward from the firewall, the VSZ is also behind a firewall with all port forwards working. I have SSIDs working with WPA2 personal fine.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I've got device auth working via radius from the APs but the replaced ZD was using a portal to let BYOD devices into the building. To allow https web portal I am trying to configure the controller for guest access rather than the APs.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I have the VSZ talking to the AD via ldap and I can type a wrong username in and it fails, I can type a correct user and it lets me in. So I look it one step further and try and get it to work with AD groups. Using the article&amp;nbsp;&lt;A alt="" href="https://support.ruckuswireless.com/articles/000010448" rel="nofollow" target="" title="Link httpssupportruckuswirelesscomarticles000010448" type="" value=""&gt;https://support.ruckuswireless.com/articles/000010448&lt;/A&gt; is put the required group into the search filter:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;eg&amp;nbsp;(objectClass=*)(memberof=CN=BYOD,CN=Users,DC=example,DC=local)&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Regardless of if the user is in the group or not the SZ authenticates the user and lets them on.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Also, annoyingly the search filter input box is limited on the number of characters, the real group name I want to use is:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;CN=Wireless - BYOD Users,OU=Wireless Configuration,DC=example,DC=local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I was hoping maybe I could use the guid for the search filter to solve the number of characters issue.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;A side issues is that the AAA Test doesn't work, the screen greys and the waiting star spins but nothing comes back.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Any suggestions would be appreciated.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Tim&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Mon, 03 Aug 2020 17:34:50 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vsz-ldap-group-access/m-p/28949#M1991</guid>
      <dc:creator>tim_guy_6698086</dc:creator>
      <dc:date>2020-08-03T17:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: vsz ldap group access</title>
      <link>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vsz-ldap-group-access/m-p/28950#M1992</link>
      <description>Of course you all knew that its not possible!!! And now I know.. So the only possibly option that I can find is Radius and using custom NAS Identifiers in in the conditions (certainly with Windows NAP Servers)&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Well that's 3 days of my life Im not going to get back.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Tim&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Wed, 05 Aug 2020 15:32:03 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/SmartZone-and-Virtual-SmartZone/vsz-ldap-group-access/m-p/28950#M1992</guid>
      <dc:creator>tim_guy_6698086</dc:creator>
      <dc:date>2020-08-05T15:32:03Z</dc:date>
    </item>
  </channel>
</rss>

