This article outlines all necessary steps to configure LDAP authentication for SSL-VPN users.
This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.
SSL-VPN Address Object

TIP: This is only a Friendly Name used for Administration.
NOTE: You can use a Network or Host as well.
SSLVPN Configuration
NOTE: The SSLVPN port will be needed when connecting using Mobile Connect and NetExtender unless the port number is 443. Port 443 can only be used if the management port of the firewall is not 443.The Domain is used during the user login process.
TIP: If you want to be able to manage the firewall via GUI or SSH over SSLVPN these features can be enabled separately here as well.
CAUTION: NetExtender cannot be terminated on an Interface that is paired to another Interface using Layer 2 Bridge Mode. This includes Interfaces bridged with a WLAN Interface. Interfaces that are configured with Layer 2 Bridge Mode are not listed in the "SSLVPN Client Address Range" Interface drop-down menu. For NetExtender termination, an Interface should be configured as a LAN, DMZ, WLAN, or a custom Trusted, Public, or Wireless zone, and also configured with the IP Assignment of Static.

CAUTION: All SSL VPN Users can see these routes but without appropriate VPN Access on their User or Group they will not be able to access everything shown in the routes. Please make sure to set VPN Access appropriately.

LDAP Settings





NOTE: This is a personal preference and does not affect.
NOTE: Make a note of which users or groups that are being imported as you will need to make adjustments to them in the next section of this article. 
User Settings
NOTE: This is dependant on the User or Group you imported in the steps above. If you imported a user, you will configure the imported user, if you have imported a group, you will access the Local Groups tab and configure the imported group.

TIP: Inorder for the LDAP users to be able to change their AD password via Netextender, make sure "ALL LDAP Users" group is added to the "SSLVPN Services" group.This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
SSL-VPN Address Object

TIP: This is only a Friendly Name used for Administration.
NOTE: You can use a Network or Host as well.

SSLVPN Configuration

CAUTION: NetExtender cannot be terminated on an Interface that is paired to another Interface using Layer 2 Bridge Mode. This includes Interfaces bridged with a WLAN Interface. Interfaces that are configured with Layer 2 Bridge Mode are not listed in the "SSLVPN Client Address Range" Interface drop-down menu. For NetExtender termination, an Interface should be configured as a LAN, DMZ, WLAN, or a custom Trusted, Public, or Wireless zone, and also configured with the IP Assignment of Static.


CAUTION: All SSL VPN Users can see these routes but without appropriate VPN Access on their User or Group they will not be able to access everything shown in the routes. Please make sure to set VPN Access appropriately.


LDAP Settings






NOTE: Make a note of which users or groups that are being imported as you will need to make adjustments to them in the next section of this article.

User Settings
NOTE: This is dependant on the User or Group you imported in the steps above. If you imported a user, you will configure the imported user, if you have imported a group, you will access the Local Groups tab and configure the imported group.


TIP: Inorder for the LDAP users to be able to change their AD password via Netextender, make sure "ALL LDAP Users" group is added to the "SSLVPN Services" group.