Software Secure Access
Activity Manage

Add a Domain Controller in Secure Access

Choose the domain controller component type and set up the domain controller to sync with Secure Access.

For LDAP or LDAPS AD queries, AD integration requires that you register an AD domain controller or AD domain in Secure Access. The Cisco AD Connector performs an LDAP sync against this domain controller or domain to retrieve the Users and Groups. The Cisco AD Connector server communicates with the domain controller on port 389 over TCP for LDAP sync or port 636 over SSL for LDAP.

The Cisco AD Connector can only retrieve users and groups from a single domain controller. If you register multiple domain controllers in Secure Access, the Cisco AD Connector only attempts to perform an LDAP sync against the first domain controller in the list. Ensure that the domain controller you are registering is not subject to any AD replication delays. Read-only Domain Controller (RODC) registrations are supported for retrieval of users and groups.

If you need to periodically bring down your domain controller for maintenance or updates or your domain controllers are behind a load balancer that does not support LDAP queries, we recommend that you register the domain instead.

Before you begin

Procedure

1

Navigate to Connect > Users and Groups > Users, click Configuration Management > Integrate directories, and then click Active Directory.

2

Click Next, and then choose Domain Controller.

Register the domain controller with Secure Access.

3

Enter the details for the domain controller.

  • Hostname—The hostname of the server where the domain controller is deployed.
  • IP version—The IP address version to use. You can use IPv4 only, IPv6 only, or Mixed IPv4 and IPv6.
  • Internal IPv4 address / Internal IPv6 address / both —The private IP address of the server where the domain controller is deployed. This field becomes available based on the IP version selection.
  • Domain—The domain where the domain controller receives the events.
4

For Active Directory site, choose a Site to associate with the domain controller.

5

Click Next, and then follow the instructions to install the AD Connector.