[Samba] ADUC missing msNPAllowDialin and need vpn advice for ad setup.
rpenny at samba.org
Thu Dec 14 10:53:32 UTC 2017
On Thu, 14 Dec 2017 11:09:52 +0100
"L.P.H. van Belle via samba" <samba at lists.samba.org> wrote:
> Im reading :
> I wanted to use the "msNPAllowDialin" , in ADUC tab "Dail-in" but i
> notices this one was gone/ i was missing this one :
> https://wiki.samba.org/images/8/88/MsNPAllowDialin.jpg Admin pc,
> windows 7 64bit, samba 4.7.3. AD Reinstalled it with the needed
> dll's from a win2008R2.
> Now my Dail in tab is shown in ADUC but when i try to open i get an
> error. I had a look in the AD with my AD browser and i see im missing
> for example : msNPAllowDialin in the AD and possible more.
> So my question, how can i add all needed properties back in the Ad
> like the msNPAllowDialin . Does samba have anything what can sort of
> restore these, samba-tool dbcheck and --cross-nc show 0 errors. Or
> should i import the radius schema and use that?
> The results where im going at is a strongswan server with user auth
> from ad/ldap with or without radius. vpn is already up and tested
> with eap-mschapv2, with plain text username/passwords and im reading
> now into the ldap part. so if anyone has some tips, that would be
The 'msNPAllowDialin' is a standard AD attribute:
If you look here:
Do not modify this value directly.
But I also found this:
From which, it seems that if you don't have the attribute, you 'Control
access through remote access policy'
If you have the attribute, it can only be set to 'TRUE' or 'FALSE'
More information about the samba