3xLOGIC v12 or newer VIGIL Central Management User Guide
- June 13, 2024
- 3xLOGIC
Table of Contents
v12 or newer VIGIL Central Management
User Guide
Tech Tip 220002
VIGIL VCM 12 – Active Directory Integration
Tech Tip #: | 200002-1 |
---|---|
Date: | March 1st , 2022 |
Product Affected: | VIGIL Central Management (VCM) v12 or newer, VIGIL Server |
v9 or newer
Purpose:| This document is intended to inform users of the process of
configuring and deploying Active Directory Integration via VIGIL VCM for both
VIGIL VCM users and managed VIGIL Server users. This document assumes the
reader has a sound knowledge of VIGIL and understands deployment process and
operation of VIGIL VCM software.
Introduction
Active Directory (AD) integration in VCM allows VIGIL Central Management to
use an AD server to manage VCM Users and/or VIGIL Server users. VCM can also
be setup to act as a proxy AD Server for VIGIL Servers that cannot access an
AD Server directly.
Note: For individual configuration of AD integration on a VIGIL Server,
the VIGIL Active Directory Manager is available and installed alongside VIGIL
Server v9 or newer systems. See 150004 TT Using VIGIL Active Directory for
more information. If using Active Directory with VIGIL VCM is desired, VIGIL
v12 or newer is required.
Configuring Active Directory with VIGIL VCM
The Active Directory Settings tab in VCM allows the user to configure settings related to the setup and usage of AD with VIGIL Central Management. For more information about the VCM AD settings form, see the table below.
Domain Settings
Domain| Enter the Active Directory server domain / IP.
Use SSL| Toggle this on if SSL / LDAPS (LDAP over SSL) authentication is
required.
Username and Password| Enter Active Directory Server login credentials.
Test| Test that the given credential can successfully login to the Active
Directory server. The user will be prompted with results when the test
completes.
General Active Directory Settings
Use Active Directory to
Manage VIGIL Server Users| Toggle this option on to have Active Directory
manage VIGIL Server Users.
VIGIL Server Should
Pass Active Directory
Request Through VCM Server| Select this option to allow VCM to act as an
Active Directory proxy for managed VIGIL that are
remote or do not exist on the same LAN as the AD server. This feature can
function over the
internet and supports VIGIL Connect.
VCM Server Address| Enter the VCM Server address for the VCM Server you would
like to act as the Active Directory proxy.
Use Active Directory to
Manage VCM Users| Toggle this option on to allow the Active Directory server
to manage VCM Users.
User Update Interval| VCM will poll the Active Directory Server for new LDAP
Group users at the defined interval.
For instructions on managing both VIGIL Server Users and VIGIL VCM Users with
AD via VCM, continue through the proceeding sections.
2.1 Manage VIGIL Server Users with Active Directory via VIGIL VCM
If VCM and VIGIL Server reside on the same LAN, VCM can be easily configured
to manage VIGIL Server’s users with Active Directory. See the below example
for more information:
To utilize this setup, follow the below instructions:
-
Using VCM Client, login to the VIGIL VCM Server that is monitoring the desired VIGIL Server.
-
Open Settings and navigate to the Active Directory settings form.
-
Enter the domain credentials for the desired Active Directory server. Test that the given credential can successfully login to the Active Directory server using the Test button. The user will be prompted with results when the test completes.
-
Toggle the Use Active Directory To Manage VIGIL Server Users option on.
-
Set an acceptable User Update Interval. The VIGIL Server user group you associate with an LDAP Group from the AD Server will be updated with changes to the LDAP group at the defined frequency.
-
Click OK to save VCM Settings.
-
Click the VIGIL Server Users button in the VCM icon toolbar.
-
Select the desired VIGIL Server group from the left-hand menu.
-
Click the Active Directory button to activate Active Directory User Management mode. Only users configured using AD will be displayed in the Users and Groups lists.
-
Click the Add Group button.
-
Enter a Name. This will be used to refer to the Server group within VIGIL VCM.
-
Associate an LDAP Group from the Active Directory Server with the Server group. Click the … button to open LDAP Search to search the Active Directory for the desired LDAP group. An LDAP Group’s users can be previewed by selecting the group and clicking the Show Users button. Select the desired group from the list of results and click OK to assign the group.
-
Apply the group’s VIGIL permissions by checking-off the desired permissions.
-
Click OK on the Add Group window to save the new group. Users from the selected LDAP group will now be added to the VIGIL Server User Group and should now populate the Users – Active Directory list. The group will be updated from the AD Server at the set User Update Interval.
-
Click Update All Servers to update servers in the selected VIGIL Server group with the new user settings. For applying user settings to an individual VIGIL Server, a user can toggle between standard VCM User Management and Active Directory User management for a singular VIGIL Server from the Server’s Edit Site Info form in VCM.
Users configured within the Active Directory LDAP groups should now be able to successfully login to applicable VIGIL Servers.
2.1.1 Use VIGIL VCM As Active Directory Proxy for VIGIL Server
In the case where a VIGIL Server cannot actively communicate with the active
directory server due to the VIGIL Server being remote, or residing on a
different LAN, the user can configure VIGIL VCM to act a proxy server for
Active Directory requests for the VIGIL Server. See the below example for
more information.
To use this setup, follow steps 1-5 from Section 2.1 and then proceed based on the following instructions:
- With the Use Active Directory to Manage VIGIL Server Users option active, toggle the VIGIL Server Should Pass Active Directory Requests Through VCM Server option on.
- Enter a VCM Server Address. This should be the address of the VCM Server you wish to act as proxy.
- Complete applicable configuration from Steps 6-15 in Section 2.1
The defined VIGIL VCM Server will now act as a proxy between the VIGIL Servers
and the AD Server.
Warning: When using the VCM as proxy, if the VCM Server experiences
downtime or internet connectivity issues, LDAP user logins for the applicable
VIGIL Servers will be unavailable as no active directory authentication
requests can be passed through an offline VCM Server.
2.2 Manage VCM Users with Active Directory via VCM
To manage VIGIL VCM’s users with Active Directory:
-
Using VCM Client, login to the VIGIL VCM Server.
-
Open Settings and navigate to the Active Directory settings form.
-
Enter the domain credentials for the desired Active Directory server. Test that the given credential can successfully login to the Active Directory server using the Test button. The user will be prompted with results when the test completes.
-
Toggle the Use Active Directory to Manage VCM Users option on.
-
Click OK to save the VCM settings.
-
Click the VCM Users button in the VCM icon toolbar.
-
Add a VCM User Group.
-
Enter a User Group Name. This is the name that will be used to refer to this VCM User Group within VCM.
-
Associate an LDAP Group with the VCM User Group. Click the … button to open LDAP Search to search the Active Directory server for the desired LDAP group. An LDAP Group’s users can be previewed by selecting the group and
clicking the Show Users button. Select the desired group from the list of results and click OK to assign the LDAP group. -
Select a Default User Type for users in this group. This will dictate which permissions the user has within VCM. See Section 9.3 VCM User Type of the VIGIL VCM User Guide for more information on the available user types and their permissions.
-
Click Edit VCM User Group Server ACL to edit the VCM access control list and configure which VIGIL Server groups can be accessed by users belonging to this VCM User group.
-
Click OK to save settings.
The VCM Users list should now populate with users from the LDAP Group selected in Step 9 of this section.
Contact Information
If you require more information, or if you have any questions or concerns,
please contact 3xLOGIC Support:
Email: helpdesk@3xlogic.com
Online: www.3xlogic.com
3xLOGIC Systems Inc. Visit us at http://www.3xlogic-en
11899 Exit 5 Parkway, Suite 100, Fishers,
IN 46037 | www.3xlogic.com | (877) 3XLOGIC
References
Read User Manual Online (PDF format)
Read User Manual Online (PDF format) >>