![Fortinet FortiRecorder 400D Administration Manual Download Page 61](http://html1.mh-extra.com/html/fortinet/fortirecorder-400d/fortirecorder-400d_administration-manual_2321737061.webp)
User management
Page 61
FortiRecorder 2.4.2 Administration Guide
3.
Configure these settings:
4.
If your directory does
not
use OpenLDAP’s default schema, or if you need to configure a
query string, query cache, LDAP protocol version, or how the query will be authenticated
Setting name
Description
Profile name
Type a name (such as
LDAP-query
) that can be referenced by other
parts of the configuration. Do not use spaces or special characters.
The maximum length is 35 characters.
Server name/IP
Type the fully qualified domain name (FQDN) or IP address of the
LDAP or Active Directory server that will be queried when an account
referencing this profile attempts to authenticate.
Fallback server
name/IP
Type the fully qualified domain name (FQDN) or IP address of a
secondary LDAP or Active Directory server, if any, that can be queried
if the primary server fails to respond according to the threshold
configured in
.
Port
Type the port number on which the authentication server listens for
queries.
The IANA standard port number for LDAP is 389. LDAPS
(SSL/TLS-secured LDAP) is 636.
Use secure
connection
If your directory server uses SSL to encrypt query connections, select
SSL
then upload the certificate of the CA that signed the LDAP
server’s certificate (see
“Uploading trusted CAs’ certificates”
Allow
unauthenticated
bind
Enable to perform the query
without
authenticating.
Disable to authenticate when querying. Also configure
,
Many LDAP servers require LDAP queries to be authenticated
(“bound”) by supplying a bind DN and password to determine the
scope of permissions for the directory search. However, if your LDAP
server does
not
require binding, you can enable this option to improve
performance.