Adding and Managing a Directory Server Profile

You can add a Directory Server profile to provide a user authentication mechanism that can be associated with one or more captive portal networks that use an Active Directory or Lightweight Directory Access Protocol (LDAP) server.

Complete the following steps to add a Directory Server profile.
  1. Add the Directory Server service to your tenant account. From the navigation bar, select Network Control > Service Catalog.
  2. Find the Directory Server tile and click Add.
    The Add Directory Server page is displayed.
  3. Enter a Directory Server profile name in the Profile Name field. The profile name must contain 2 to 32 alphanumeric characters.
  4. Select one of the following Server Type options:
    • Active Directory Server: Allows clients to authenticate with an Active Directory server.
    • LDAP Server: Allows clients to authenticate with an LDAP server.
  5. (Optional) Disable Enable TLS encryption if encrypted communication is not required.
    Note: Enable TLS encryption is enabled by default to encrypt data transmitted between clients and servers.
  6. Enter a valid domain name or IP address in the FQDN or IP Address field.
  7. Enter a port number in the Port field. The valid range is from 1 through 65,535.
    • The default port number is 636 when Enable TLS encryption is enabled.
    • The default port number is 389 when Enable TLS encryption is disabled.
  8. Complete the server-specific fields based on the selected server type:
    • Active Directory Server
      • Enter a valid domain name in the Windows Domain Name field. The format is dc=domain, dc=ruckuswireless, dc=com.
      • Enter a valid administrator domain name in the Admin Domain Name field. The format is admin@domain.ruckuswireless.com.
    • LDAP Server
      • Enter a valid domain name in the Base Domain Name field. The format is dc=ldap, dc=com.
      • Enter a valid administrator domain name in the Admin Domain Name field. The format is cn=admin, dc=ldap, dc=com.
      • (Optional) Enter a key attribute to identify users in the Key Attribute field. The default value is uid.
      • (Optional) Enter a filter used to retrieve LDAP directory server entries in the Search Filter field. For example, objectClass=* returns all objects in the LDAP directory.
  9. Enter a password in the Admin Password field.
  10. Click Test Connection to test the Active Directory or LDAP server connection.
    The test result is displayed.
  11. (Optional) Enter values in the following fields in the Identity Attributes & Claims Mapping section:
    • Identity Display Name
    • Identity Email
    • Identity Phone
    Note: If Identity Display Name is empty or does not match a value returned by the directory server, the username is displayed.
  12. (Optional) Click Add custom field.
    The Identity Attribute Mapping section is displayed.
    • Select an Attribute Type from the drop-down list. The following attribute types are available: First Name, Last Name, User Principal Name, Title, Groups, Roles, Department, Organization, and Address.
    • Enter a value in the Claim Name field.

    To add additional mappings, click Add custom field again.

  13. Click Add.
    The Directory Server profile is added to the Directory Server page.

    A notification is displayed on the Activities page. Click the icon in the upper-right corner of the RUCKUS One web interface to access the page. Click a Directory Server profile to view configuration details, identity attribute mappings, and associated instances that display the network name and network type.

    The page displays the following information:

    • Name: Displays the name of the Directory Server profile.
    • Server Type: Displays the server type (Active Directory or LDAP).
    • Server Address: Displays the FQDN or IP address along with the port.
    • Domain Name: Displays the configured domain name in the format dc=domain, dc=ruckuswireless, dc=com.
    • Networks: Displays the number of networks currently associated with the Directory Server profile.

    You can use the Search option to display only the table entries matching the specified name; enter a minimum of two characters. Additionally, you can filter the list of Directory Server profiles by selecting an option from the drop-down list in the Networks field.

    You can customize which fields appear in the Directory Server table by clicking the icon and selecting or deselecting the desired column names. Drag and drop individual column names up or down the list to customize the left‑to‑right column display in the table. Optionally, you can click Reset to default to have the default subset of columns appear in the Directory Server table. Click Clear Filters to reset the filters. You can sort the list of Directory Server profiles by clicking the associated column header.

  14. Select the checkbox alongside the profile name to display the management options:
    • Edit: Allows you to edit the Directory Server profile.
    • Delete: Allows you to delete the Directory Server profile.
      Note: You cannot delete a profile that is associated with a network.