Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    LDAP users are not displayed

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 3 Posters 881 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pixel24
      last edited by

      Hi@all,

      I have connected the pfSense to the local LDAP server (UCS server).

      I have previously imported the UCS rootCA. This is also displayed correctly. Subsequently:

      • Authentication server +

      0479dec5-ad05-4d45-9518-3f7e4e547cba-image.png

      0cc12326-2b75-4c13-b32f-aab37f9662a1-image.png
      218eec65-bcda-475d-a636-17ec82e3b21d-image.png

      When I test a user with a password under Diagnostics -> Authentication, I get an OK.

      Under User Administration -> Settings -> Save & Test I get:

      0d659957-cc0c-4c9f-a328-d76399eb7ca4-image.png

      Looks good to me. However, no LDAP users are shown in the pfSense in the user administration. What have I forgotten?

      with best
      pixel24

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        The firewall will not display LDAP users in a list. It will only attempt to authenticate users against LDAP when they attempt to login.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        P 1 Reply Last reply Reply Quote 2
        • P
          pixel24 @jimp
          last edited by

          can I use the LDAP users for OpenVPN users on the pfSense?

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by stephenw10

            Yes.
            https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/configure-server-backend.html

            But for user auth only, you can't pass parameters like you can with Radius.

            Steve

            1 Reply Last reply Reply Quote 0
            • P
              pixel24
              last edited by

              ok, I will use the LDAP connection. I have created the group "OpenVPN" in the LDAP. Is it possible to restrict openVPN access to this group?

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                No. You can have the users inherit the privileges of a matching local group. But since there is no privilege required to connect to OpenVPN you can't restrict users using that directly.

                https://docs.netgate.com/pfsense/en/latest/usermanager/groups.html#groups-and-remote-authentication

                Steve

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  You could define an LDAP auth server entry just for OpenVPN which has settings that limit it to only the container or filter corresponding to the OpenVPN group on the server, then have OpenVPN auth against that.

                  Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 1
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Ooo, nice!

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.