LDAP
User
FortiGate Version 4.0 Administration Guide
576
01-400-89802-20090424
ou=marketing,dc=fortinet,dc=com
where
ou
is organization unit and
dc
is a domain component.
You can also specify multiple instances of the same field in the distinguished name, for
example, to specify multiple organization units:
ou=accounts,ou=marketing,dc=fortinet,dc=com
Binding is said to occur when the LDAP server successfully authenticates the user and
allows the user access to the LDAP server based on his or her permissions.
You can configure the FortiGate unit to use one of three types of binding:
•
anonymous - bind using anonymous user search
•
regular - bind using user name/password and then search
•
simple - bind using a simple password authentication without a search.
You can use simple authentication if the user records all fall under one dn. If the users are
under more than one dn, use the anonymous or regular type, which can search the entire
LDAP database for the required user name.
If your LDAP server requires authentication to perform searches, use the regular type and
provide values for user name and password.
To add an LDAP server, go to
User > Remote > LDAP
and
select
Create New
. Enter the
information below and select OK.
Figure 380: LDAP server configuration
Name
Enter the name that identifies the LDAP server on the FortiGate unit.
Server Name/IP
Enter the domain name or IP address of the LDAP server.
Server Port
Enter the TCP port used to communicate with the LDAP server.
By default, LDAP uses port 389.
If you use a secure LDAP server, the default port changes when you
select Secure Connection.
Query
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...