Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Difficulties when combining Pfsense with UCS Linux

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    8 Posts 2 Posters 846 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I Offline
      isaaclondo09
      last edited by

      95282786-7861-4911-993c-ee67660392a6-image.png

      I am trying to join the AD that I have with UCS with my Pfsense but I am having problems joining with the LDAP, this is the configuration I have so far, when I check the containers I get this error Could not connect to the LDAP server. Please check the LDAP configuration.

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        Have you connected to it from anything else? How is that configured?

        Check the states when you try to connect. Do you see two way traffic?

        I 1 Reply Last reply Reply Quote 0
        • I Offline
          isaaclondo09 @stephenw10
          last edited by

          @stephenw10 I already have the ldap configured with Windows AD and it joins without problems, but with the UCS at the time of entering the BIND credentials it is not able to connect.

          image (3).png image (4).png image (1).png image (2).png

          1 Reply Last reply Reply Quote 0
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by stephenw10

            Do you need to import the CA cert perhaps? Does the server cert contain that IP as a SAN? If not use the fqdn there.

            Does it allow unencrypted connections like you are trying in that second screenshot?

            I 1 Reply Last reply Reply Quote 0
            • I Offline
              isaaclondo09 @stephenw10
              last edited by

              @stephenw10
              When the option Use anonymous binds to resolve distinguished names is enabled and I verify the union with the LDAP if the BIND option passes. I am going to show you the configuration that I have with an LDAP but united with Windows Server and I have the same configuration as such, only the option that is different changes when a new LDAP Server is added in the INITIAL TEMPLATE option for Windows server porner Microsoft AD and for LINUX OpenLDAP.
              In turn, I am going to export the server and put the FQDN of the LDAP server

              image (6).png image (5).png

              1 Reply Last reply Reply Quote 0
              • stephenw10S Offline
                stephenw10 Netgate Administrator
                last edited by

                Hmm, so it does bind if you remove encryption and authentication?

                Does the server show an error when it tries to query the OUs?

                I 1 Reply Last reply Reply Quote 0
                • I Offline
                  isaaclondo09 @stephenw10
                  last edited by

                  @stephenw10
                  Exactly, if I remove the option for both LDAP in Windows and Linux it works, the situation is that you must have the administrator user so that you can find the OUs and with UCS the error appears

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Offline
                    stephenw10 Netgate Administrator
                    last edited by

                    Hmm, what's different in pfSense? You can't login as an admin user?

                    You don't have to 'discover' OUs, you can just enter the query directly.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.