MSM7xx Controllers Configuration Guide v6.4.0
Using an Active Directory server
Active Directory is the Windows service that is used by many organizations for user authentication.
The controller can communicate with an Active Directory server to authenticate user login credentials
and retrieve configurations settings (attributes) that are applied to a users session.
An active directory server can be used to support the following authentication types:
For details, see ...Service
“802.1X authentication” (page 334)802.1X (VSC)
“MAC-based authentication” (page 132)MAC-based (Global)
“MAC-based authentication” (page 132)MAC-based (VSC)
“HTML-based authentication” (page 347)HTML-based
“VPN-based authentication” (page 349)VPN-based
NOTE: The controller cannot join an Active Directory domain if the domain uses multiple DNS
servers balanced by the Round Robin feature.
Supported protocols
• EAP-PEAP
• EAP-TLS
• EAP-TTLS: Requires that client stations are configured to use MS-CHAP or MS-CHAP-V2.
Active Directory configuration
To configure active directory support, select Controller >> Authentication > Active Directory.
NOTE: It is important that the system time on the controller is accurate when an Active Directory
server is being used. To set the time select Controller >> Management > System time.
Using an Active Directory server 369










