User Management
Configuring the User Authentication Settings
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
283
9
Using LDAP for Authentication
The security appliance can use the LDAP directory for user authentication, with
support for three schemes including Microsoft Active Directory, RFC2798
InterOrgPerson, and RFC2307 Network Information Service.
STEP 1
Click
Users
-> Settings
.
The User Settings window opens.
STEP 2
In the
User Login Settings
area, choose
LDAP
as the authentication method from
the
Authentication Method
drop-down list.
STEP 3
Click
Configure
to configure the LDAP settings.
The LADP Settings window opens.
STEP 4
In the
Settings
tab, enter the following information:
•
IP Address:
Enter the IP address of the LDAP server that you use for
authentication.
•
Port Number:
Enter the number of the listening port used on the LDAP
server. Enter a value from 1 to 65535. The default is 389.
•
Server Timeout:
Enter the amount of time in seconds that the security
appliance will wait for a response from the LDAP server before timing out.
•
Login Method:
Choose one of the following login methods:
-
Annonymous Login:
Choose this option if the LDAP server allows for the
user tree to be accessed anonymously.
-
Give Login Name or Location in Tree:
Choose this option to build the
distinguished name of the user that is used to bind to the LDAP server
from the
Primary Domain
and
User Tree for Login to Server
fields in the
Directory
tab.
-
Give Bind Distinguished Name:
Choose this option if the destination
name is known. You must provide the destination name explicitly to be
used to bind to the LDAP server.
•
Login User Name:
If you choose
Give Login Name or Location in Tree
or
Give Bind Distinguished Name
as the login method, enter the user name of
the account that can log into the LDAP directory.