HiveManager NG - Active Directory RADIUS

  • 2
  • Question
  • Updated 9 months ago
Hi All,

Is any one else using Active Directory authentication with HiveManager NG? I cant seem to get it working.

When ever I do a RADIUS test it keeps telling me the shared secret is incorrect, and when trying to browse our directory to select a group it says an error has occurred.

However when I added the server it seemed to add ok with no problems.

In regards to the shared secret I couldnt find anywhere to input the share secret into the client, I found it when setting up the server I assume this sets it on the client side as well

Any help would be appreciated.

Thanks!
Photo of Kyle Heading

Kyle Heading

  • 9 Posts
  • 1 Reply Like

Posted 3 years ago

  • 2
Photo of Nick Lowe

Nick Lowe, Official Rep

  • 2491 Posts
  • 451 Reply Likes
Hi Kyle,

Prima facie, you appear to be confusing using an external RADIUS server with using the built-in Aerohive RADIUS server.

Do you have an external RADIUS server that you wish to use with something like NPS, FreeRADIUS or Radiator?

Or do you wish the Aerohive APs to bind to your Active Directory so that the built-in RADIUS server can be used?

Nick
(Edited)
Photo of Kyle Heading

Kyle Heading

  • 9 Posts
  • 1 Reply Like
Hi nick

Thanks for the quick reply

I would like to use the I built in radius server, this is the way we had setup previously in the old hive manger

If we need to we also have a FreeRadius sever onsite but we found the in built one easier to configure for use with Aerohive

Cheers
Photo of Nick Lowe

Nick Lowe, Official Rep

  • 2491 Posts
  • 451 Reply Likes
Did you see the bit where HM-NG states "All Aerohive devices within the same Hive are configured by default as approved RADIUS Clients."?

I think you need to get to the bottom of why your APs cannot interact with your directory first.
(Edited)
Photo of Kyle Heading

Kyle Heading

  • 9 Posts
  • 1 Reply Like
i did not and now I have removed the radius client settings its working fine

Thanks for your help!
Photo of Kyle Heading

Kyle Heading

  • 9 Posts
  • 1 Reply Like
ooops spoke to soon.

The radius test works ok, which is good. However when I try to assign a different network profile based on a AD group it tells me an error occurred and wont let me browse our directory

ill keep working on it...
Photo of Andres Oton

Andres Oton

  • 1 Post
  • 0 Reply Likes
Hello,

We have the same issue. Did you find a solution?

I can write the group name and then save the policy but then I get a second issue. If the user is member of several groups the radius bultin server doesn't report all groups and the assignament doesn't work properly.

Regards,
Photo of Edward Marshall

Edward Marshall

  • 7 Posts
  • 0 Reply Likes

Hello,

Did you ever get this working? We are having the same issue: our AH Radius server can connect to AD, lookup the user but the user always gets the default profile as the AD group cannot be matched... Seems that if the users has many group memberships, it doesn't match?

Regards,

Edward

Photo of Kyle Heading

Kyle Heading

  • 9 Posts
  • 1 Reply Like
Nope this is a bug in NG I have been chasing Aerohive for nearly 12 months now we are remaining on the old HiveManager until this is fixed

I'm surprised more people are not complaining about it . This is a major bug and something I would assume is essential for more enterprise clients
Photo of Edward Marshall

Edward Marshall

  • 7 Posts
  • 0 Reply Likes
That's unfortunate. I will open a support ticket with AH and see what they say. We're in the process of migrating our hive to NG so hopefully can find a solution / workaround to this in the next few of days while we still have the Christmas holidays!

Thanks for your message - I'll let you know how we get on.

Regards,

Edward
Photo of Kyle Heading

Kyle Heading

  • 9 Posts
  • 1 Reply Like
Yeah it would be great to know how you go but as I said I have had a support case with Aerohive for this for quite a while but as we are still working on the old system and I'm to busy to follow up on they haven't been working on it much

Please let me know how you go :)
Photo of Aaron Valente

Aaron Valente

  • 42 Posts
  • 3 Reply Likes
I am only just poking around NG initially but are there no settings available in the AAA server settings or LDAP server settings? I recal using LDAP mapping for this type of issue in HMOL...
Photo of Ricccardo

Ricccardo

  • 1 Post
  • 0 Reply Likes
Hi ,

I have exactly the same problem , connection with AD works but only read a default user group , We opened a ticket 2 weeks ago but we are waiting yet for an answer ....
Photo of Luke Harris

Luke Harris

  • 265 Posts
  • 18 Reply Likes
Another reason to stay put. I use AD for MAC-Auth for corporate devices. 
Photo of Juan Dominguez

Juan Dominguez

  • 9 Posts
  • 0 Reply Likes
Hi, 

Any news, about that bug ?

Thanks
Photo of Edward Marshall

Edward Marshall

  • 7 Posts
  • 0 Reply Likes

Yes, it's fixed now in NG. We're running version: 11.25.1.1

Photo of Juan Dominguez

Juan Dominguez

  • 9 Posts
  • 0 Reply Likes
Hi,

Thanks for your fast reply Edward.