Configuring DNS and Verifying Readiness for Cloudpath to Join Active Directory Domain

Perform the following steps to configure DNS and verify that the Active Directory server is ready to be joined by Cloudpath:

  1. Configure DNS. Active Directory uses DNS in the background to locate other domain controllers and services, such as Kerberos. Therefore, Active Directory domain members and servers must be able to resolve the Active Directory DNS zones. The following describes how to manually configure Cloudpath to use DNS servers:
    1. Log into your Cloudpath system from the command line as cpn_service.
    2. Run the show config command. Check if there is a DNS (nameserver) entry for your Active Directory server. Typically, the existing /etc/resolv.conf file contains only the DNS nameserver entry of the local host. If your Active Directory server is in a different DNS nameserver, follow the next step to add the Active Directory nameserver.
    3. Run the command: config network STATIC dns nameserver_ip1 nameserver_ip2 to add nameservers into the /etc/resolv.conf file, as follows:
      • nameserver_ip1
      • nameserver_ip2

      If there is more than one nameserver for multiple Active Directory servers in the PEAP domain, you can add multiple nameservers. However, the /etc/resolv.conf file has a limit of three nameserver entries.

    4. Run the show config command again. Verify that the nameservers are correctly configured.
  2. . Test DNS resolution: On the Cloudpath UI, go to Support> Diagnostics, then click the DNS Lookup tab.
    • Forward lookup: Enter the fully qualified domain name (FQDN) of your AD server (such as msft-dc-2012.demo.sample.local) in the Server DNS field, then click the Run button. Check that the returned IP address is the IP address of the AD server.
    • Reverse lookup: Enter the IP address of your AD server in the Server DNS field, then click the Run button. Check that the returned name is the host name of the AD server.
  3. Ping the AD server. Verify that you can ping the FQDN under the Ping tab in the Support > Diagnostics portion of the UI. If the ping is not successful, check the network connectivity between the Cloudpath server and your AD server.
  4. Test the Cloudpath connection to the AD Server:
    1. Go to the Configuration > Authentication Servers portion of the UI.
    2. Click the right-pointing green arrow to the right of the AD whose connection you are testing.
    3. On the ensuing "Test" popup window, enter the credentials for a user in that AD, then click Continue.
    4. You will receive a success or failure message, along with other pertinent information.