User`s guide

1.
2.
3.
4.
1.
2.
3.
1.
2.
3.
4.
1.
2.
3.
1.
2.
3.
To configure Active Directory:
Go to the page.USERS > External Authentication
Click the tab.Active Directory
In the table, edit or add an Active Directory authentication configuration for one or more domain controllers.Basic
In the table, you can create or delete group filter patterns. For more information, see .Patterns Group Filter Patterns
NTLM
If your network uses an NT LAN Manager (NTLM) authentication server, your NTLM domain users are transparently authenticated using their
Microsoft Windows credentials. This single sign-on method of access control is provided by transparent proxy authentication against the your
NTLM server. To enable transparent proxy authentication against your NTLM server, you must join the Barracuda Firewall to the NTLM domain as
an authorized host.
To enable NTLM user authentication:
Go to the page.USERS > External Authentication
Click the tab.NTLM
Enter the settings for your NTLM server and then click .Save
LDAP
Lightweight Directory Access Protocol (LDAP) is used for storing and managing distributed information services in a network. LDAP is mainly
used to provide a single sign-on solution. It follows the same X.500 directory structure as MSAD.
To configure LDAP:
Go to the page.USERS > External Authentication
Click the tab.LDAP
In the table, edit or add LDAP authentication configurations for one or more domain controllers.Basic
In the table, you can create or delete group filter patterns. For more information, see .Patterns Group Filter Patterns
RADIUS
Remote Access Dial In User Service (RADIUS) is a networking protocol providing authentication, authorization, and accounting. The Barracuda
Firewall uses RADIUS authentication for the IPsec, client-to-site, and SSL VPN.
To enable integration with RADIUS:
Go to the page.USERS > External Authentication
Click the tab.RADIUS
Enter the settings for your RADIUS server and then click .Save
OCSP
Online Certificate Status Protocol (OCSP) is a protocol used to verify if X.509 certificates have been revoked by their respective CAs. The
Barracuda Firewall can use the information provided by an OCSP server to verify the authenticity of a certificate.
For integration with OCSP-based online digital certification verification:
Go to the page.USERS > External Authentication
Click the tab.OCSP
Enter the settings for your OCSP server and then click . Save
Group Filter Patterns
For Active Directory and LDAP, you can use group filter patterns. These patterns are typically used in large environments to filter unwanted group
membership information and are not affected by authentication against the Active Directory or LDAP. You can use wildcard characters in the
patterns.
For example, if you use the following group filter pattern:
*SSL*
And the following group membership strings are used: