25.Troubleshooting authentication tasksThis chapter provides information to troubleshoot authenticationissues. For information about SSL VPN commands or concepts go tohttps://www.nortel.com/Navigation• “Troubleshooting RADIUS authentication” (page 25)• “Troubleshooting LDAP authentication with Active Directory” (page 37)• “Configuring LDAPs authentication with Active Directory” (page 41)• “Importing certificates” (page 44)• “Troubleshooting NTLM authentication with Primary Domain Controller”(page 46)Troubleshooting RADIUS authenticationThe IAS checks the Active Directory to validate a username/passwordwhen a RADIUS authentication request arrives from the SSL VPNgateway. Further, it returns an attribute in the RADIUS authenticationresponse that will map the user to the correct group/groups in the SSLVPN configuration. The user can use the network user name, as defined inActive Directory, when authenticating.ATTENTIONThe configuration attributes given in this section are just examples. Theattributes that you need to specify for configuration can be different than this.Troubleshooting RADIUS authentication navigation• “Configuring RADIUS settings” (page 26)• “Integrating authentication service” (page 27)Nortel VPN GatewayTroubleshooting GuideNN46120-700 01.01 Standard12 October 2007Copyright © 2007 Nortel Networks.