Active Directory
The NetProfiler provides a user identity feature that maps active directory (AD) usernames with IP addresses. This feature enables you to view:
Figure: Users Logged into a Given Host for a Selected Time Period
Figure: Hosts That a Given User Logged into for a Selected Time Period
This feature relies on the security audit events obtained from one or more Microsoft active directory domain controllers. You can send this event data directly to the NetProfiler from a domain controller, or for AD-2008, an event collector host. Riverbed provides a service application named SteelCentral AD Connector that forwards the appropriate events from a domain controller, or event collector, to the NetProfiler.
Integration for Active Directory 2008
For AD-2008, you must use the SteelCentral AD Connector 2.0. You can install the connector on either the domain controllers or an event collector, but Riverbed recommends that you install the AD Connector on the event collector. Even though installation on a domain controller is easier, you must install it as many times as the number of domain controllers. The installation on an event collector requires a few more steps, including planning of event-collecting topology (if not already implemented in the environment), but it requires no additional product installed on domain controllers and provides more flexible delivery paths.
For more information about configuring integration with AD-2008, see the documentation provided on the Riverbed Support site.
You can download the connector and the document from either the Riverbed support site or directly from the NetProfiler help downloads page.
Integration for Active Directory 2003
For AD-2003, you must use the SteelCentral AD Connector 1.5. You can install the connector on the domain controllers or another Windows server acting as a collector within the same domain controller, but Riverbed recommends that you install the connector on the domain controller. Installing the connector directly on the domain controller requires no messaging between the domain controllers and an external collector, whereas if you use the external collector, you need significant inter-system communications.
For more information about configuration integration with AD-2000 and AD-2003 environments, see Technical Note #29: Microsoft AD Integration for User Identity.
You can download the connector and the document from Riverbed Support or directly from the NetProfiler help downloads page.