Yi Dong The deep convincing firewall
-----AD Domain Integration
In the environment of life, or in the enterprise environment, there will be a Microsoft AD domain environment, then we are convinced that the next generation of firewalls also have a certification system, if for this device alone to do the authentication of the user's trouble, for users may have different passwords, will cause a lot of trouble. Deep conviction can be integrated into the system's domain environment, so that users can directly use their own original domain user name and password.
Let's take a simple look at the test environment.
650) this.width=650; "Width=" 553 "height=" 134 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
The experimental environment is also relatively simple, allowing the device to connect to AD domain, and DNS is also ready to point to the domain server. Let's take a look at the simple, practical operation.
One: Add a role (AD domain)
650) this.width=650; "Width=" 484 "height=" 202 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 526 "height=" 387 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 526 "height=" 369 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 469 "height=" 217 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 421 "height=" 432 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>650) this.width=650, "width=" 404 "height=" 435 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/E /u261/lang/zh-cn/images/localimage.png ") no-repeat center;border:1px solid #ddd;" alt= "Spacer.gif"/>
650) this.width=650; "width=" 429 "height=" 436 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 461 "height=" 199 "src="/e/u261/themes/default/images/ Spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid # DDD, "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 501 "height=" 434 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>650) this.width=650, "width=" 430 "height=" 441 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/E /u261/lang/zh-cn/images/localimage.png ") no-repeat center;border:1px solid #ddd;" alt= "Spacer.gif"/>650) this.width=650, "width=" 554 "height=" 293 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/E /u261/lang/zh-cn/images/localimage.png ") no-repeat center;border:1px solid #ddd;" alt= "Spacer.gif"/>
Two: Add roles (AD Federation Service)
650) this.width=650; "Width=" 529 "height=" 411 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "width=" 524 "height=" 409 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 531 "height=" 408 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "width=" 535 "height=" 408 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
Three: Test whether the local domain reads properly
with LDAP B rowser to test if LDAP can be read by someone else
650) this.width=650; "Width=" 441 "height=" 334 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 441 "height=" 332 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "width=" 445 "height=" 335 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 405 "height=" 335 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 554 "height=" 336 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
Four: Set the interface and zone of the deep convincing firewall
Network Configuration > interface/area > area
650) this.width=650; "Width=" 522 "height=" 323 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
Network Configuration > interface/area > area
650) this.width=650; "width=" 535 "height=" 310 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
Five: Modify the device default DNS server
Network Configuration > Advanced network configuration > DNS
650) this.width=650; "Width=" 383 "height=" 318 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
VI: Test the feasibility of firewall devices and DNS
System Maintenance > Command Line console
650) this.width=650; "Width=" 509 "height=" 287 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
Seven: Add an external authentication server
authentication System > External authentication server > New > LDAP Server
650) this.width=650; "Width=" 323 "height=" 503 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" "height=" 423 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 379 "height=" 434 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 205 "height=" + "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
Eight: Add external groups and import external users
Authentication Systems > Groups/Users > New > Groups
650) this.width=650; "Width=" 554 "height=" 280 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
Authentication System > User import > Import from an external LDAP server
650) this.width=650; "Width=" 554 "height=" 367 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 366 "height=" 137 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 554 "height=" 155 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 554 "height=" 324 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
Import AD Domain Users
650) this.width=650; "width=" 423 "height=" 438 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 353 "height=" 208 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
Nine: Divide the corresponding users into corresponding groups
Authentication Systems > Groups/Users > All Users > Mobile
650) this.width=650; "Width=" 554 "height=" 271 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
650) this.width=650; "Width=" 554 "height=" 336 "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/images/localimage.png") no-repeat center;border:1px solid #ddd; "alt=" Spacer.gif "/>
Now that we have imported users from the domain directly onto a deeply convincing firewall, we can do some related certifications based on these users.
This article from "11837699" blog, declined reprint!
The depth of the shield convincing firewall-----AD domain Integration