30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

16.4 User accounts in Active Directory — domain mapping<br />

The first page of the wizard requires the full name of the Active Directory domain (e.g.<br />

company.com) and name and password of a user with rights to add hosts to domains.<br />

If <strong>Kerio</strong> Control cannot find the domain server of the specified domain automatically, it<br />

requires specification of its IP address in the next step. Then the user gets informed about the<br />

result of the attempt to add the firewall to the domain.<br />

Primary domain mapping<br />

To set mapping of the primary domain (the domain of which the firewall host is a member),<br />

use option Use domain user database. For connection to the domain server, it is required to<br />

enter username and password of an account with read rights for the user database (any user<br />

account of the domain can be used, unless it is blocked).<br />

Figure 16.12<br />

Primary domain mapping<br />

Advanced Options<br />

Method of cooperation between <strong>Kerio</strong> Control and the Active Directory can be customized by<br />

some advanced options.<br />

Domain mapping vs domain user authentication<br />

The recommended method of cooperation with the Active Directory is domain mapping<br />

(user accounts are saved and managed only in the Active Directory). However, this<br />

can be undesirable under certain circumstances. For example if the Active Directory is<br />

implemented in a network where the Windows NT domain or no domain has been used,<br />

user accounts are already created in the <strong>Kerio</strong> Control’s local database. In such case,<br />

the best solution is to keep the local accounts and set only authentication in the Active<br />

Directory (so that users can use the same password both for the domain and the firewall).<br />

231

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!