Search...
Menu

SANGFOR_IAG_v13.0.80_Domain_SSO_Configuration_Guide

Author: Jojo

Sangfor Internet Access Gateway (IAG) V13.0.80 Domain Single Sign-On (SSO) Configuration Guide

Version 01 (Mar.24, 2021) Confidentiality: Public in Company 1

Sangfor Internet Access Gateway (IAG)

Domain Single Sign-On (SSO) Configuration Guide

Product Version

13.0.80

Document Version

01

Released on

April. 22, 2024

Introduction

A customer uses a Microsoft AD server to manage intranet users who are on Windows systems. The customer wants to control the intranet users' online behavior and traffic information while also performing identity verification for these users. Among the several ways of combining Microsoft AD domain authentication, the script SSO has the highest success rate. However, the customer does not allow scripts to be delivered through the Microsoft AD domain. Here, we can choose the domain SSO method.

Configuration Steps

A diagram of a computer server Description automatically generatedThe configuration steps are as shown in the figure below. It should be noted that to make everyone familiar with the AD domain faster, we added the AD domain configuration method, which is the part marked as not necessary. You may focus on configuring IAG if the AD domain has already been deployed.

Configure Active Directory Server

Install MS AD Function

  1. Open Server Manager in Windows Server 2019.

A screenshot of a computer Description automatically generated

  1. A screenshot of a computer Description automatically generatedOn the Dashboard, click Add roles and features to open the Add Roles and Features Wizard.

  2. On the Before You Begin tab, click Next.

A screenshot of a computer Description automatically generated

  1. On the Installation Type tab, select Role-based or feature-based installation. Then click Next.

A screenshot of a computer Description automatically generated

  1. On the Server Selection tab, choose Select a server from the server pool, and then click Next.

A screenshot of a computer Description automatically generated

  1. A screenshot of a computer Description automatically generatedOn the Server Roles tab, select the functions that need to be installed, such as Active Directory Domain Services and DNS Server, then click Next.

  2. On the Features tab, select Group Policy Management, and click Next.

A screenshot of a computer Description automatically generated

  1. On the AD DS tab, click Next to proceed.

A screenshot of a computer Description automatically generated

  1. On the DNS Server tab, click Next to continue.

A screenshot of a computer Description automatically generated

  1. On the Confirmation tab, check the Restart the destination server automatically if required checkbox. Then click Install.

  2. Wait for the installation to complete. You can view the installation progress on the Results tab.

A screenshot of a computer Description automatically generated

  1. Click Close after the installation is complete.

A screenshot of a computer Description automatically generated

Configure the Domain Controller

  1. Open Server Manager. On the Dashboard, click Promote this server to a domain controller.

A screenshot of a computer Description automatically generated

  1. A screenshot of a computer Description automatically generatedAfter entering the Active Directory Domain Services Configuration Wizard, on the Deployment Configuration tab, select Add a new forest and specify the Root domain name for the AD domain, such as sangfor.com.

  2. On the Domain Controller Options tab, set a password.

A screenshot of a computer Description automatically generated

  1. On the DNS Options tab, click Next to proceed.

A screenshot of a computer Description automatically generated

  1. On the Additional Options tab, set The NetBIOS domain name. You can use the default NetBIOS name SANGFOR.

  1. On the Paths tab, click Next to proceed.

A screenshot of a computer Description automatically generated

  1. On the Prerequisites Check tab, select Install to start the installation.

A screenshot of a computer Description automatically generated

  1. Wait for the equipment to install and deploy related functions.

A screenshot of a computer Description automatically generated

  1. After the installation is complete, the Windows Server will automatically restart.

A blue screen with white text Description automatically generated

  1. A screenshot of a login screen Description automatically generatedAfter the Windows Server restarts, you can see on the login page that the default local administrator, who logs in to the operating system, has become the administrator in the domain, and the login password is the same as the password of the local administrator account.

Create Usernames and Passwords for Other Users on the Domain

Open Active Directory Users and Computers.

A screenshot of a computer Description automatically generated

  1. To facilitate the management of users according to the company's organizational structure, navigate to the domain name sangfor.com and expand it. Right-click and select New > Organizational Unit to create a logical container to represent a department. For example, create a department named Sangfor Tech.

A screenshot of a computer Description automatically generated

A screenshot of a computer Description automatically generated

  1. Right-click the container, and select New > User to create a user in the container. For example, sangfortest.

A screenshot of a computer Description automatically generated

A screenshot of a computer Description automatically generated

  1. Set a login password for this user.

A screenshot of a computer Description automatically generated

  1. Click Finish to complete the settings for creating the user.

A screenshot of a computer Description automatically generated

Join the PC to the Domain

  1. Configure the PC's network card, and set the DNS to the IP address of the domain control server: 192.168.1.4.

A computer screen with a network and internet settings Description automatically generatedA screenshot of a computer Description automatically generated

A screenshot of a computer Description automatically generated

A screenshot of a computer Description automatically generated

  1. Join the PC to the domain.

A screenshot of a computer Description automatically generated

A screenshot of a computer Description automatically generated

A screenshot of a computer error Description automatically generated

A screenshot of a computer Description automatically generated

  1. A screenshot of a computer security Description automatically generatedDuring the process of joining the domain, you need to verify your identity. You can use the sangfortest user account created on the AD domain controller 192.168.1.4 for testing.

  2. After successfully joining the domain, you need to restart the PC.

A screenshot of a computer Description automatically generatedA screenshot of a computer screen Description automatically generatedA computer screen with a blue background Description automatically generated

  1. After restarting, you will see the login page of the PC. Choose to use the domain account sangfortest to log in.

A screenshot of a login screen Description automatically generated

Enable the AD Server Log Audit Function

  1. Open Run.

A screenshot of a computer Description automatically generated

  1. Enter gpmc.msc in the Run dialog box to open the Group Policy Management console.

A screenshot of a computer error Description automatically generated

  1. A screenshot of a computer Description automatically generatedRight-click the Default Domain Controllers Policy and select Edit to open the Group Policy Management Editor.

  2. Right-click Audit account logon events and Audit logon events, then select

Success and Failure.

A screenshot of a computer Description automatically generated

  1. A screenshot of a computer Description automatically generatedRun the gpupdate /force command in CMD to forcibly refresh the group policy.

Configuration in IAG

Add LDAP Server

  1. On the IAG web console, navigate to Access Mgt > Authentication > Web Authentication > Auth Server. Click Add > LDAP Server to add a Microsoft AD server on IAG.

A screenshot of a computer Description automatically generated

  1. Pay attention to the username that needs to be entered with the complete domain name in the Admin DN field. You can use the newly created sangfortest@sangfor.com, but it is usually recommended to use the administrator account to avoid the lack of permissions that cause IAG to fail to interact with the Microsoft AD server. You can choose sangfor for the BaseDN.

A screenshot of a computer Description automatically generated

  1. A screenshot of a computer Description automatically generatedIf IAG and AD Server can interact normally, navigate to Access Mgt > User Management > Local Users. You can see that IAG has obtained the domain user information of the AD server, including the user sangfortest that we created earlier.

Configure Domain SSO Authentication

  1. A computer screen shot of a computer Description automatically generatedNavigate to Acess Mgt > Authentication > Web Authentication > Single Sign-On(SSO) > MS AD Domain. Select Enable Domain SSO and Domain SSO. Then, click Add to add a domain controller. Configure the parameters according to the preset Microsoft AD server.

Configure Authentication Policy on IAG

  1. Navigate to Access Mgt > Authentication > Web Authentication > Authentication Policy to configure the authentication policy. Click Add to enter the Auth Policy dialog box. On the Objects tab, specify the scope of the authentication policy in the IP/MAC Address field, where the IP address should match the authentication policy.

A screenshot of a computer Description automatically generated

  1. On the Auth Method tab, select Single sign-on (SSO) for the Auth Method.

A screenshot of a computer Description automatically generated

  1. Restart the user’s PC and log in with a domain account. You can see that the user is online in IAG and the authentication method is SSO on the Status > Users > Online Users list.

A screenshot of a computer Description automatically generated

Precautions

  1. The strict security mechanisms or firewall of Windows Server may prevent other devices from obtaining relevant data from the AD Server. Adjust the security policy if necessary.

  2. It is recommended to use the domain account with administrator privileges to avoid insufficient permissions when the IAG obtains the security logs for SSO authentication purposes.

  3. Ensure that the users’ inbound and outbound traffic passes through the IAG. IAG will identify the user traffic before marking the user on the online user list.

Sangfor Internet Access Gateway (IAG) V13.0.80 Domain Single Sign-On (SSO) Configuration Guide

Version 01 (April.22, 2024) 32

Share this Article
Previous
Best Practice
Next
Sangfor_CC_v3.0.92_Update Security Database via Proxy Server Configuration Guide_Reviewed
Last modified: 2025-03-05Powered by