Active Directory integration over cloud with v4.2.5 of NxFilter and NxCloud.

178 views
Skip to first unread message

Jahastech

unread,
Apr 20, 2018, 7:30:23 PM4/20/18
to NxFilter
Active Directory integration over cloud is now possible. We use NxRelay for this. For NxFilter, it's a full scale Active Directory implementation. For NxCloud, it's still partial implementation. However, even with NxCloud, your operators will be able to see Active Directory username on their GUI log-view and they can apply a specific policy based on Active Directory username.

To find out more read the tutorial part on the following link,
  http://www.nxfilter.org/tutorial.html#ad-integration-nxrelay

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 8:35:49 PM4/22/18
to NxFilter
I do not know where I should place the IP of my server nxcloud. ??

In logging signal, I see the communication between nxrelay and the operator console ...

My question is the following:

Configure the operator token in nxrealy.
Now as I must do for other users. from the local network ...

The tutorial is not clear ..

Help me please.

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 8:43:16 PM4/22/18
to NxFilter
On DHCP Server what´s setup DNS Primary and Secundary...???

Jahastech

unread,
Apr 22, 2018, 8:46:18 PM4/22/18
to NxFilter
Your NxCloud is a policy server for NxRelay. So set your NxRelay's server_ip to be your NxCloud IP.

And NxRelay is a relaying DNS server for your local network. For your users, NxRelay is the DNS server for them.

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 8:51:06 PM4/22/18
to NxFilter
Error !!


Jahastech

unread,
Apr 22, 2018, 8:52:18 PM4/22/18
to NxFilter
Use NxRelay as your only DNS server. It's a relaying DNS server.

Jahastech

unread,
Apr 22, 2018, 8:56:32 PM4/22/18
to NxFilter
I guess you installed it on a domain controller. Did you add one more IP and set it listening only one IP? Otherwise you get a port collision problem.

This is for NxFilter but it's also effective for NxRelay.
  https://www.youtube.com/watch?v=v2iIuhcTpsU

And use the latest version of NxCloud and NxRelay.

Jahastech

unread,
Apr 22, 2018, 8:57:49 PM4/22/18
to NxFilter
If it is a port collision read this first.
  http://www.nxfilter.org/doc/faq.html#bind-ip

And check your log file first.

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 9:02:06 PM4/22/18
to NxFilter
So, my dhcp config : IP, netmas, gateway DNS1: nxrelay.(X.X.X.55)

IP MS AD: 1th: X.X.X.50
                  2th: X.X.X.55  (Created for NXRELAY).
DNS1: X.X.X.55

CONFIG nxrelay:
server: nxcloud ip.
login token: token operator.
localdns: X.X.X.50
domain: xxxx.local
listen ip: X.X.X.55

This configuration correct?


Jahastech

unread,
Apr 22, 2018, 9:06:16 PM4/22/18
to NxFilter
It seems OK. Test it and if you have a problem enable debugging on both NxRelay and NxCloud and show me your log files.

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 9:10:38 PM4/22/18
to NxFilter

Ok, now last error! install nxrelay as services...

Jahastech

unread,
Apr 22, 2018, 9:12:33 PM4/22/18
to NxFilter
So what did it say in your log file? /nxrelay/log/nxrelay.log.

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 9:16:22 PM4/22/18
to NxFilter
I send the log nxrelay
nxrelay.log

Jahastech

unread,
Apr 22, 2018, 9:19:35 PM4/22/18
to NxFilter
ERROR [04-22 20:18:17] - USr, java.net.BindException: Address already in use: Cannot bind
 INFO [04-22 20:18:17] - USr, Couldn't bind UDP/53. You might want to check your permission!

Try to run it on CMD and see if you stil have that port collision. And read the tutorial or watch the tutorial video and probably set your MS DNS to listen just one IP.

Jahastech

unread,
Apr 22, 2018, 9:22:14 PM4/22/18
to NxFilter
Judging by these log,
 
 INFO [04-22 21:19:13] - EventMon.readEvent, evtId = 4624, uname = ANONYMOUS LOGON, ip = 180.180.1.13, evt = S-1-0-0,-,-,0x0,S-1-5-7,ANONYMOUS LOGON,NT AUTHORITY,0x14b9f7,3,NtLmSsp ,NTLM,SRVBIOMETRIC,{00000000-0000-0000-0000-000000000000},-,NTLM V1,128,0x0,-,180.180.1.13,2708.
 INFO [04-22 21:19:13] - EventMon.readEvent, 180.180.1.13 - ANONYMOUS LOGON, added into IP session dictionary.
 INFO [04-22 21:19:28] - DnsStats.flush, udpCnt = 5, aclDropCnt = 0, queryCnt = 5, customCnt = 0, authRediCnt = 0, authDropCnt = 0
 INFO [04-22 21:19:28] - NPr, Sending PING.

It may work fine. What do you see on your NxCloud log-view then?

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 9:28:03 PM4/22/18
to NxFilter
It´s fine ..!!

Today only logs, user administrator connect for me... on AD.
Tomorrow login the users... how view request their.??
lognxcloudrequest.png

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 9:30:12 PM4/22/18
to NxFilter
This error it´s because, set up firewall forwarding port udp 53. NXCLOUD----> NXRELAY Now config and connect fine.

Jahastech

unread,
Apr 22, 2018, 9:32:03 PM4/22/18
to NxFilter
What do you mean by 'Tomorrow login the users... how view request their'? I don't understand what you are saying.

Jahastech

unread,
Apr 22, 2018, 9:33:52 PM4/22/18
to NxFilter
Befoer you ask, read our tutorial thoroughly. Active Directory implementation with NxCloud is still partial. It's not full scale. If you want a full scale solution, go with NxFilter combined with NxRelay. You can import users and groups with them.

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 9:36:42 PM4/22/18
to NxFilter
Ok, now I'm configuring nxcloud and nxrelay. But in the company there is no user connected or who has logged in. That's why the request I see in the log, are only those that I have made with the administrator session from the MS AD.

Tomorrow at the start of the working day all users will come to work and will log in. In that scenario how will the logs request ???

Could I differentiate each user ?? as indicated in the manual
operator @ user .. ??

Jahastech

unread,
Apr 22, 2018, 9:38:56 PM4/22/18
to NxFilter
You will see your username in this form,

  tokenname _adusername

And if you create a user having the same name from your Active Directory on NxCloud GUI then you can assign a different policy on the user.

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 9:43:19 PM4/22/18
to NxFilter
I must create the same AD user in GUI Nxcloud of the operator.

I understand that with the Nxcloud GUI, I control my global clients ...??

And in the GUI of nxcloud / operator I control the users for each client ..??

Jahastech

unread,
Apr 22, 2018, 9:46:07 PM4/22/18
to NxFilter
When you login to NxCloud as an admin, you control operators. And when you login as an operator, you control user level policies.

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 9:55:56 PM4/22/18
to NxFilter
So, where I do create the users? GUI Operator or GUI Admin ???
I don´t understand

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 10:06:57 PM4/22/18
to NxFilter
My idea is to sell the webfiltering service to my clients. and give them a console where they can manage their profiles or policies for each user.

But I control every client from nxcloud.

....................................?

Jahastech

unread,
Apr 22, 2018, 10:07:03 PM4/22/18
to NxFilter
If you don't understand that maybe NxCloud is not for you. Why did you use it if you are not a service provider? On NxCloud AD integration is for operators. They install NxRelay for their local network. So they create users on their operator GUI.

If you don't think aobut this, and you are not a service provider you have no reason for using NxCloud. NxFilter is better for you.

Jahastech

unread,
Apr 22, 2018, 10:23:10 PM4/22/18
to NxFilter
Create it on operator GUI. AD integration is for each operator. So you need to do it on operator GUI.

Jose Antonio Saavedra Añez

unread,
Apr 22, 2018, 10:37:49 PM4/22/18
to NxFilter
Thanks you for you help!

I´m service provider ;). 

Tomorrow I do verify users logon request...!

Good nigth. My friend.

Jahastech

unread,
May 14, 2018, 7:02:22 PM5/14/18
to NxFilter
A bug found with NxCloud v4.2.5 and it's patched. The bug is about operator request count not being reset on midnight and you get 'Too many requests' error on operator level as a result.
Reply all
Reply to author
Forward
0 new messages