SonicOS 6.5 introduces support for user authentication partitioning and multiple LDAP servers.
NOTE: Multiple LDAP servers are supported on all platforms.
Authentication partitioning is a high‐end feature that is only relevant for customers whose networks are big enough to encompass multiple Active Directory forests, etc. User authentication partitioning provides a mechanism for LDAP, RADIUS, and/or Single‐Sign On (SSO) authentication in an environment where you manage multiple non‐interconnected domains. Such an environment needs users in a particular domain to be authenticated via the specific:
What User authentication partitioning means?
CAUTION: Users authentication Partitioning is available only on NSA 2650 and above, and all SuperMassive platforms.
The partitions configured under Authentication Partitions control which authentication servers are used for which users, where those users are in different network partitions. The policies configured under Partition Selection Policies define the selection of the above partitions based on the physical location of users being authenticated. When authenticating users whose domain names are not available for matching against those in the above partitions, the users’ partitions are selected based on their physical locations as set by these policies. These policies are also used for auto‐assigning authentication devices to partitions based on physical location of the devices. By clicking Add under Authentication Partitions, you can add either a top level partition or a sub‐partition.
Authentication partitions select the LDAP servers, RADIUS servers, SSO agents, and TSAs used to authenticate particular users. In addition to assigning the servers and agents to a partition, it may be necessary to assign certain of them to different subsets of the users in the partition. Sub‐partitions allow assigning particular agents for certain subsets of a partition’s users if specific ones need to be used for them. If an authentication partition isset as a sub‐partition of another one, then agentsspecific to the top level, or parent, authentication partition’s users can be assigned to the sub‐partition. The sub‐partition’s agents are used when relevant, but the servers and agents of the parent partition can be used as appropriate.
Multiple primary LDAP servers can be configured, one for each authentication partition, plus a list of additional servers for each. More than two RADIUS servers can also be configured. When adding an authentication server or SSO/TS/RADIUS Accounting agent in the Users | Settings page, you must select the authentication partition if more than one partition is configured. Multiple authentication partitions will usually require using different DNS servers to resolve the host names in the different partitions. In SonicOS 6.5, the Split DNS feature is separated from DNS Proxy to accommodate this configuration. The Split DNS configuration is moved from the DNS Proxy page to the main Network | DNS page. DNS servers configured in Split DNS are now used directly for DNS lookups of host names in internal domains.
To configure Split DNS:
NOTE: Sub-partitions allow assigning particular agents etc. for certain subsets of a partition's users if specific ones need to be used for them. If an authentication partition is set as a sub-partition of another one, then agents etc. specific to its users can be assigned to it so that those will be used when relevant, but also allowing the servers and agents of the parent partition to be used, as appropriate (see below).
EXAMPLE: take a scenario where it is necessary to locate SSO agents at each of a number of remote sites in order for those agents to be able to identify the users there, while the LDAP and RADIUS servers are all located at the central site. For this, each of the remote sites can be configured as a sub-partition of the central site, with the SSO agent(s) at a remote site assigned to its sub-partition. Then, after selecting the relevant agent from the sub-partition to identify a user at the remote site, the user's group memberships would subsequently be looked up via the LDAP servers of the parent partition.
Some special cases for sub-partitions are: