Re: [Freeipa-users] FreeIPA and Pulse Secure (Juniper SSLVPN)

2016-01-12 Thread CFMS Support
Hi Alexander, I've just had a call with Pulse Secure, and we've worked out the various problems, thanks for your help as that really helped with Pulse Secure. FYI, and for anyone in the future; The User filter should be uid=, The Group filter should be cn= and both member attribute and query att

Re: [Freeipa-users] FreeIPA and Pulse Secure (Juniper SSLVPN)

2016-01-12 Thread Alexander Bokovoy
On Tue, 12 Jan 2016, CFMS Support wrote: Hi Alexander, Yes I see that as well actually, and when looking for a specific group I get: [12/Jan/2016:10:30:50 +] conn=30648 fd=114 slot=114 connection from 172.19.6.16 to 172.20.3.6 [12/Jan/2016:10:30:50 +] conn=30648 op=0 EXT oid="1.3.6.1.4.

Re: [Freeipa-users] FreeIPA and Pulse Secure (Juniper SSLVPN)

2016-01-12 Thread CFMS Support
Hi Alexander, Yes I see that as well actually, and when looking for a specific group I get: [12/Jan/2016:10:30:50 +] conn=30648 fd=114 slot=114 connection from 172.19.6.16 to 172.20.3.6 [12/Jan/2016:10:30:50 +] conn=30648 op=0 EXT oid="1.3.6.1.4.1.1466.20037" name="startTLS" [12/Jan/2016:

Re: [Freeipa-users] FreeIPA and Pulse Secure (Juniper SSLVPN)

2016-01-12 Thread Alexander Bokovoy
On Tue, 12 Jan 2016, CFMS Support wrote: Hi Alexander, These are the entries from /var/log/dirsrv/slapd-/access [12/Jan/2016:10:22:13 +] conn=30642 fd=128 slot=128 connection from 172.19.6.16 to 172.20.3.6 [12/Jan/2016:10:22:13 +] conn=30642 op=0 EXT oid="1.3.6.1.4.1.1466.20037" name="s

Re: [Freeipa-users] FreeIPA and Pulse Secure (Juniper SSLVPN)

2016-01-12 Thread CFMS Support
Hi Alexander, These are the entries from /var/log/dirsrv/slapd-/access [12/Jan/2016:10:22:13 +] conn=30642 fd=128 slot=128 connection from 172.19.6.16 to 172.20.3.6 [12/Jan/2016:10:22:13 +] conn=30642 op=0 EXT oid="1.3.6.1.4.1.1466.20037" name="startTLS" [12/Jan/2016:10:22:13 +] conn=

Re: [Freeipa-users] FreeIPA and Pulse Secure (Juniper SSLVPN)

2016-01-12 Thread CFMS Support
Hi Alexander, In fact, I have specified one of the rules as a direct username and can log in to it using that username and password. However, it's just the group membership that isn't working. Kind Regards, Josh Cullum On Tue, Jan 12, 2016 at 10:09 AM CFMS Support wrote: > Hi Alexander, > > B

Re: [Freeipa-users] FreeIPA and Pulse Secure (Juniper SSLVPN)

2016-01-12 Thread Alexander Bokovoy
Hi Josh, On Tue, 12 Jan 2016, CFMS Support wrote: Brilliant thanks. I still don't seem to be able to see any users, and cannot sign in as a user from one of the groups that I can see. Do you have any ideas about groups, I'm only picking up 8 static groups when Member Attribute is set to membero

Re: [Freeipa-users] FreeIPA and Pulse Secure (Juniper SSLVPN)

2016-01-12 Thread CFMS Support
Hi Alexander, Brilliant thanks. I still don't seem to be able to see any users, and cannot sign in as a user from one of the groups that I can see. Do you have any ideas about groups, I'm only picking up 8 static groups when Member Attribute is set to memberof (Filter is cn= and DN is cn=groups,c

Re: [Freeipa-users] FreeIPA and Pulse Secure (Juniper SSLVPN)

2016-01-12 Thread Alexander Bokovoy
On Tue, 12 Jan 2016, CFMS Support wrote: Hi All, New to the mailing list, fairly new to IPA. We have three IPA servers in a cluster in a staging environment. We're looking to replace AD with IPA as we are mostly Linux based and we have just bought some new Pulse Secure Appliances to replace our