
server, it attempts to contact the second server and so on. When a
connection is made and an authentication response received (either positive
or negative) it is treated as definitive. It does not then contact further
servers because all servers are assumed to have identical content.
Using Transport Layer Security (TLS) with Active Directory
authentication
TLS is a cryptographic protocol which provides security between applications
over a network.
For Active Directory authentication, the SMU supports up to TLS 1.2. It
negotiates with the domain controller to use the highest version of TLS which
is common to both.
The SMU requires domain controllers to respond on port 389. It is not
possible to configure the SMU to use any other port.
Configuring Active Directory servers
Global Administrators can provide information to configure, modify, and list
Active Directory servers for authentication on the
Active Directory Servers
page.
Before you begin
In order to enable Active Directory use, the SMU administrator needs to know
the following information:
• The domain in which the Active Directory users and groups that will access
the SMU are located.
• The LDAP distinguished name and password of an Active Directory user
that has read access to users and groups on the Active Directory servers.
This is referred to as the Search User. The user can search for users or
groups under the supplied base distinguished name.
• The addresses of one or more Active Directory servers that maintain the
users and groups for the domain. The content of all configured servers
must be identical. If DNS servers have been configured for the SMU, then
the SMU should be able to automatically discover these server addresses
via the
find servers
button on the setup page. SRV records must be setup
in order for
find servers
to find the Active Directory servers.
• The Active Directory group or groups whose members are to be given the
right to log into the SMU.
• If RADIUS was previously in use and it is to be replaced by Active
Directory, then the RADIUS configuration must first be removed before
Active Directory can be configured. This is done from the
Home>SMU
Administrator>RADIUS Servers
page by clicking the
remove all
settings
button. No RADIUS user will be able to log into the SMU after
this is done.
230
Setting up security
System Administrator Guide for VSP Gx00 models and VSP Fx00 models
Summary of Contents for VSP F400
Page 10: ...10 System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Page 16: ...16 Preface System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Page 210: ...210 User administration System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Page 244: ...244 Setting up security System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Page 256: ...256 Alert notifications System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Page 270: ...270 Managing license keys System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Page 386: ...386 System option modes System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Page 406: ...406 Glossary System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Page 412: ...412 Index System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...
Page 413: ...System Administrator Guide for VSP Gx00 models and VSP Fx00 models ...