• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Difficulties when combining Pfsense with UCS Linux

Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
8 Posts 2 Posters 358 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • I
    isaaclondo09
    last edited by Feb 20, 2025, 1:59 PM

    95282786-7861-4911-993c-ee67660392a6-image.png

    I am trying to join the AD that I have with UCS with my Pfsense but I am having problems joining with the LDAP, this is the configuration I have so far, when I check the containers I get this error Could not connect to the LDAP server. Please check the LDAP configuration.

    1 Reply Last reply Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Feb 20, 2025, 4:42 PM

      Have you connected to it from anything else? How is that configured?

      Check the states when you try to connect. Do you see two way traffic?

      I 1 Reply Last reply Feb 20, 2025, 4:55 PM Reply Quote 0
      • I
        isaaclondo09 @stephenw10
        last edited by Feb 20, 2025, 4:55 PM

        @stephenw10 I already have the ldap configured with Windows AD and it joins without problems, but with the UCS at the time of entering the BIND credentials it is not able to connect.

        image (3).png image (4).png image (1).png image (2).png

        1 Reply Last reply Reply Quote 0
        • S
          stephenw10 Netgate Administrator
          last edited by stephenw10 Feb 20, 2025, 5:11 PM Feb 20, 2025, 5:10 PM

          Do you need to import the CA cert perhaps? Does the server cert contain that IP as a SAN? If not use the fqdn there.

          Does it allow unencrypted connections like you are trying in that second screenshot?

          I 1 Reply Last reply Feb 20, 2025, 5:25 PM Reply Quote 0
          • I
            isaaclondo09 @stephenw10
            last edited by Feb 20, 2025, 5:25 PM

            @stephenw10
            When the option Use anonymous binds to resolve distinguished names is enabled and I verify the union with the LDAP if the BIND option passes. I am going to show you the configuration that I have with an LDAP but united with Windows Server and I have the same configuration as such, only the option that is different changes when a new LDAP Server is added in the INITIAL TEMPLATE option for Windows server porner Microsoft AD and for LINUX OpenLDAP.
            In turn, I am going to export the server and put the FQDN of the LDAP server

            image (6).png image (5).png

            1 Reply Last reply Reply Quote 0
            • S
              stephenw10 Netgate Administrator
              last edited by Feb 20, 2025, 6:14 PM

              Hmm, so it does bind if you remove encryption and authentication?

              Does the server show an error when it tries to query the OUs?

              I 1 Reply Last reply Feb 20, 2025, 7:36 PM Reply Quote 0
              • I
                isaaclondo09 @stephenw10
                last edited by Feb 20, 2025, 7:36 PM

                @stephenw10
                Exactly, if I remove the option for both LDAP in Windows and Linux it works, the situation is that you must have the administrator user so that you can find the OUs and with UCS the error appears

                1 Reply Last reply Reply Quote 0
                • S
                  stephenw10 Netgate Administrator
                  last edited by Feb 20, 2025, 9:20 PM

                  Hmm, what's different in pfSense? You can't login as an admin user?

                  You don't have to 'discover' OUs, you can just enter the query directly.

                  1 Reply Last reply Reply Quote 0
                  1 out of 8
                  • First post
                    1/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received