1-21
Cisco Wide Area Application Services Configuration Guide
OL-26579-01
Chapter 1 Configuring Administrative Login Authentication, Authorization, and Accounting
Configuring Administrative Login Authentication and Authorization
Step 13 Register the chosen device (or device group) with the Windows Domain Controller as follows:
a. Click the Domain Join tab. (See Figure 1-6.)
Figure 1-6 Domain Join Tab
b.
In the User Name field, enter a username (the domain\username or the domain name plus the
username) for the specified Windows Domain Controller. This must be the username and password
of a user who has administrative privileges in Active Directory (permission to add a computer to a
domain).
For NTLM, the user credentials can be any normal user belonging to the Domain Users group. For
Kerberos, the user credentials must be a user that belongs to the Domain Admins group, but need
not be the system default Administrator user.
Note To use Windows domain server authentication, the WAAS device must join the Windows
domain. For registration, you will need a user credential with permission to join a machine
to the Windows domain. The user credential used for registration is not shown in clear text
anywhere, including log files. WAAS does not modify the structure or schema of Windows
Active Directory.
Note A domain join is required for encrypted MAPI acceleration using a machine account.
c. In the Password field, enter the password of the specified Windows Domain Controller account.
d. In the Confirm password field, reenter the password of the specified Windows Domain Controller.
e. (Optional) If desired, enter the name of the organizational unit in the Organizational Unit field (for
Kerberos authentication only).
f. Click the Join button.
Note When you click the Join button, the WAAS Central Manager immediately sends a
registration request to the WAAS device (or all of the devices in the device group) using SSH
(the specified domain administrator password is encrypted by SSH). The registration request
instructs the device to perform domain registration with the specified Windows Domain
Controller using the specified domain username and password. If the device is accessible (if
it is behind a NAT and has an external IP address), the registration request is performed by
the device (or device group).
Comments to this Manuals