14.02.2014 Views

CommandCenter Secure Gateway - Admin Guide - Version ... - Raritan

CommandCenter Secure Gateway - Admin Guide - Version ... - Raritan

CommandCenter Secure Gateway - Admin Guide - Version ... - Raritan

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 12: Remote Authentication<br />

Synchronize All AD Modules<br />

You should synchronize all AD Modules whenever you change or delete a<br />

user in AD, change user permissions in AD, or make changes to a domain<br />

controller.<br />

When you synchronize all AD modules, CC-SG retrieves the user groups<br />

for all configured AD modules, compares their names with the user groups<br />

that have been imported into CC-SG or associated with the AD module<br />

within CC-SG, and refreshes the CC-SG local cache. The CC-SG local<br />

cache contains all domain controllers for each domain, all user groups that<br />

are associated with modules in CC-SG, and the user information for the<br />

known AD users. If user groups have been deleted from the AD modules,<br />

CC-SG removes all associations to the deleted group from its local cache<br />

as well. This ensures that CC-SG has the most current AD user group<br />

information.<br />

To synchronize all AD modules:<br />

1. Choose <strong>Admin</strong>istration > Security.<br />

2. Click the Authentication tab. All configured Authorization and<br />

Authentication Servers appear in a table.<br />

3. In the On Demand Synchronization list, select All Active Directory<br />

Modules, then click the arrow button. A confirmation message<br />

appears when all AD modules have been successfully synchronized.<br />

If changing the password for a user in MSFT Windows Server 2003 AD,<br />

both of old and new passwords are valid for around 30 minutes. During<br />

this period, the user can log into CC-SG with either password. This is<br />

because the AD is caching the old password for 30 minutes before the<br />

new password is fully updated.<br />

Enable or Disable Daily Synchronization of All AD Modules<br />

To enable daily synchronization of all AD modules:<br />

1. Choose <strong>Admin</strong>istration > Security.<br />

2. Click the Authentication tab. All configured Authorization and<br />

Authentication Servers appear in a table.<br />

3. Select the Daily synchronization of All Modules checkbox.<br />

4. In the Synchronization Time field, click the up and down arrows to<br />

select the time at which you want CC-SG to perform the daily<br />

synchronization of all AD modules.<br />

5. Click Update to save your changes.<br />

144

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!