This message was deleted.
# citrix-netscaler
s
This message was deleted.
d
This is what comes up in aaadebug: cascade_authorization 0-0: Authorization failed for all confiugured servers
r
what auth group are you putting that user in?
d
im not using individual users, adding a group to superuser
and it looks like its not extracting groups when comparing aaadebug with the one from the working netscaler
just tested with individual user and it seems to work. so something with group or group exctraction
r
I made a group called ADC-Admins, and put that group in superuser, and i have radius return ADC-Admins to put the AD user in that group
d
I am not using Radius
ldap authentication
r
ahhh, ok. Sorry, just trying provide what I have working. 🙂
d
makes sense. I have the same ldap config working on 3 other devices. something is diff on this one and I cant find what exactly
r
yeah, that's odd
d
ok looks like the search fileter is an issue. Without it everything works. I think it does not like the group being in different OU from user accounts. But again.. this is not a problem on other similar devices 🤷‍♂️
r
Yeah, that's an odd one.
d
so to close this, I changed the base dn on the LDAP server page to just root ad and then added a search filter to check group membership. that way other accounts wont be able to logon.
m
be careful with setting the base dn to the root because if your AD is large you will get timeouts
👍 1
You can add 1.2.840.113556.1.4.1941 to the Search Filter so it searches through nested groups. Without this, users will need to be direct members of the filtered group.
👍 1
d
thanks @Mike Streetz (O_P) lots of good info. I did notice with base dn at the root that logons to the management console slowed down by 1-2 seconds. As far as the group membership its not nested in my case but great to know. I am still curious why the same identical filter works on my onprem gateways but does not on the Azure one. All devices are running the same ver. The only diff the on prem have been around longer and have been upgraded from lower versions.
m
are the azure ones pointing to on prem AD?
d
yea to exact same LB pool
m
that is weird then
it might be timing out?
have you tried doing a aaad.debug while logging in?
d
I did and lots of output but nothing that really jumps at me except on the working devices it eventually listed groups the user was a member of. and on the azure one it kept logging cascade_authorization 0-0: Authorization failed for all confiugured servers
but in both cases it contacted DC's with no issues
c
its been two weeks but still... I wanted to test 14.1 ADC firmware and ended up in same error when I tried to import license file with nsroot account. I have created another local account and added it to super user group. With that account I am able to perform all operations without any issues. Not able to modify nsroot permissions.