The Directory Service Settings section lets you configure the settings to sync SDP users between your account and an LDAP domains, such as Active Directory (AD).
This is the workflow to use Directory Services to integrate an LDAP domain with your Cato account:
When you add an LDAP domain to your account, you need to add a Directory Service connection to the Cato Management Application. Each domain and child domain in your organization needs a separate connection in the Directory Service Settings window. For example, if your account has the domains sample.com, alpha.sample.com, and example.com, then you need to create three connections in Directory Service Settings.
For the domain Password, the maximum length of a password is 48 characters.
When you enter the distinguished names (DNs) for the domain:
-
Login DN refers to the object in the LDAP directory hierarchy for the admin
-
Base DN refers to the object in the LDAP directory hierarchy for the users and groups that the admin is syncing with Cato
To add a domain to the Cato Management Application:
-
From the navigation menu, click Access > Directory Services.
-
From the LDAP section or tab, and click New.
The New Directory Service panel opens.
-
Enter the Name of the domain in the LDAP server.
-
In the LDAP Authentication Description section, configure the Login DN:
-
For on-premise AD, use the AD account Distinguished Name (DN)
-
For an Azure AD, use the AD account User Principal Name (UPN)
-
-
In Base DN, enter the LDAP domain components.
-
Enter the Password for the CN user that you created for the Directory Services connection.
-
For LDAP domains that use an SSL connection, select Encryption.
The domain is added to the Cato Management Application. Configure the Domain Controllers for the domain.
Add the Domain Controller (DC) that is associated with the LDAP server to the Directory Services domain.
For LDAP servers that are behind a site, you can you can add the DC using the IP address or as a host that is defined for a site (Network > Sites > <site name> > Site Configuration > Hosts).
For servers that are external and use a public IP address, you can define the DC using an IP address or the domain.
Note
Note: Make sure that firewalls or routing devices are configured correctly for the following deployments:
-
The DC resides behind an IPsec site (instead of a Socket)
-
All of the traffic isn't routed to the Socket
You need to contact Support to obtain the source IP address of the LDAP sync. Make sure that traffic to and from this IP address is routed inside the Cato tunnel.
To add a domain controller:
-
In the navigation menu of the New Directory Service panel, click Domain Controllers.
-
Define the connection settings to the DC depending on its location:
-
For DCs on a host defined behind a site, select Internal Host, and then select the static host for the LDAP server
-
For DCs that use an internal IP address, select Internal IP and enter the IP address for the DC
-
For DCs that aren't behind a site, select External IP or Domain, and enter the IP address or domain for the DC
-
-
Click Add.
-
For deployments with multiple DCs, repeat the previous steps to add each DC.
-
Click Save and Close.
After you define the domain and add the DC, we recommend that you test the connectivity between the domain and the Cato Management Application.
The Cato Management Application automatically tests connectivity to all the DCs for the domain, and shows the results for each DC.
If the connectivity test is unsuccessful, see Troubleshooting Directory Services and User Awareness Errors and Issues for troubleshooting recommendations.
To test the connectivity to the domain:
-
From the Connection column for the domain, click Test connection. The Cato Management Application shows the results of the connectivity test.
After you add the DCs, configure the settings that define how to synchronize the SDP users in the LDAP groups.
-
By default, all security policies are applied to both Directory Service users and their corresponding VPN User profiles.
-
If you are using Directory Services and you need to modify an SDP user's mobile phone number for MFA, only modify the phone number in the LDAP directory
-
Select the LDAP groups that are synchronized your account.
-
Enable or disable automatically synchronizing the SDP users each day.
-
Define the behavior for users that are removed from the LDAP group - to disable or to remove them from the Cato Management Application.
Select the LDAP groups that Directory Services imports from the domain to your account. The Configuration > Groups window marks imported groups as LDAP groups.
You can configure the Cato Management Application to automatically send invitation emails after new users are imported. The emails contain information about installing the Cato Client on a computer or device. For more information, see Configuring User Provisioning for Cato Clients.
Note
Note: Make sure that there are enough SDP user licenses in your Cato account for the LDAP users (System > Licenses). Otherwise, the sync fails and there is an error message.
To select the AD groups that are imported to your account:
-
In the New Directory Service panel, click User Groups.
-
In User Groups for Directory Service, in Select User Groups, select the groups that you are syncing with your account.
Configure the Synchronization settings for this domain (see below).
You can enable your account to automatically synchronize each day with the LDAP directory, and update the groups and SDP users in the Cato Management Application to match those in the domain. You can also choose to add a prefix to the imported LDAP groups and users in the Cato Management Application. This prefix lets you easily distinguish between imported users and users that you manually create.
Cato starts the daily automatic LDAP sync for all accounts at 12:00 am UTC. Cato performs the sync one account at a time, and it can take several hours to complete the daily sync of all accounts.
Note
Note: For accounts with multiple domains, the synchronization settings must be the same for all the domains in your account. Otherwise, there can be issues related to possible trust dependencies between the different domains.
SDP Users that No Longer Exist in Directory Service Groups
The If SDP user no longer exists in imported Directory Service groups setting lets you define the synchronization behavior when users or groups are deleted from the LDAP server or have expired or been disabled. You can choose from the following options:
-
Disable - the users are disabled and can't connect to the Cato Cloud. The user remains in User Groups they were members of
-
Remove - the users accounts are removed from the Cato Management Application, including from User Groups they were members of
When groups or users are removed from the LDAP server, but they are used by an object or rule in the Cato Management Application, this is the sync behavior:
-
Users are disabled instead of deleted
-
Groups are marked as no longer synced
-
The groups or users are labeled as Manual instead of LDAP
-
By default, the Cato Management Application prevents accounts from deleting or disabling more than 100 users as part of the LDAP sync. At the start of the LDAP sync, if the sync will delete or disable more than the 100 users (for the default setting), then the sync is cancelled and an email notification is sent. You can disable preventing deleting or disabling users, or change the maximum number of deleted users per LDAP sync.
Configure the settings for the sync between the domain and your Cato account. You choose to enable a daily automatic sync, and the behavior when a user is removed from a Directory Service group.
Changes that are made in the AD, are with automatically synced with the Cato Management Application (at 12:00 am UTC daily), or on demand by the administrator.
To configure the synchronization settings for a domain:
-
Manage the automatic sync settings:
-
In the New Directory Service panel, select User Groups.
-
In the User Groups section, select to enable or disable Daily Sync User Groups.
The toggle is green when enabled.
-
-
Define the behavior If SDP user no longer exists in imported Directory Service groups in the AD domain:
-
Disable the user in the Cato Management Application
-
Remove the user from the Cato Management Application
-
-
(Optional) Customize the setting for Prevent deleting more than a number of users during LDAP sync:
-
To change the how many users that can be deleted during LDAP sync, in users, enter the maximum number of deleted users.
-
To remove the limit of how many users that can be deleted during LDAP sync, disable
this setting.
-
-
(Optional) In Add prefix to imported groups, enter the prefix that is automatically added to the names for Groups and SDP users in the Cato Management Application.
-
Click Apply and then click Save.
The domain is configured to sync users and groups with your account.
Use the Sync Now feature to manually synchronize groups and SDP users between the AD server and the Cato Management Application. For accounts with multiple domains, The Cato Management Application synchronizes all domains simultaneously (because there can be trust dependencies between domains).
To manually sync the Directory Services for all domains:
-
From the navigation menu, click Access > Directory Services.
-
In the LDAP section or tab, click Sync Now.
-
After a short time, a window opens and summarizes the sync. If changes were detected, click either:
-
Review Changes - to review the changes before performing the updates.
-
Perform Updates - to perform the sync and update the Cato Management Application and the domain servers.
-
You can delete domains and DCs when they are no longer needed.
Note
Note: Deleting domains and DCs is permanent and you can't undo the delete.
To delete a domain:
-
From the navigation menu, click Access > Directory Services.
-
In the LDAP section or tab, in the row of the domain click
.
-
Click Save. The domain is deleted from your account.
To delete a domain controller:
-
From the navigation menu, click Access > Directory Services.
-
In LDAP section or tab, edit the domain.
The Edit Directory Services panel opens.
-
In the navigation menu of the New Directory Service panel, click Domain Controllers.
-
In the row with the DC, click
.
-
Click Apply and then click Save. The DC is deleted from the domain.
Comments
0 comments
Article is closed for comments.