© Copyright Lenovo 2017
Chapter 39: Secure Input/Output Module
591
Implementing Secure LDAP (LDAPS)
Lightweight
Directory
Access
Protocol
(LDAP)
is
a
protocol
for
accessing
distributed
directory
information
services
over
a
network.
Enterprise
NOS
uses
LDAP
for
authentication
and
authorization.
With
an
LDAP
client
enabled,
the
switch
will
authenticate
a
user
and
determine
the
user’s
privilege
level
by
checking
with
one
or
more
directory
servers
instead
of
a
local
database
of
users.
This
prevents
customers
from
having
to
configure
local
user
accounts
on
multiple
switches;
they
can
maintain
a
centralized
directory
instead.
As
part
of
SIOM,
you
can
implement
Secure
Lightweight
Directory
Access
Protocol
(LDAPS)
in
addition
to
standard
LDAP.
Enabling LDAPS
When
the
IOM
is
in
SIOM
mode,
all
LDAP
configurations
are
made
from
the
CMM
and
pushed
to
the
IOM.
When
the
IOM
is
in
LIOM
mode,
the
CLI
can
be
used
to
configure
LDAP
settings.
LDAPS
is
disabled
by
default.
To
enable
LDAPS:
1.
Turn
LDAP
authentication
on
2.
Enable
LDAP
Enhanced
Mode:
This
changes
the
ldap-server
subcommands
to
support
LDAPS.
3.
Configure
the
IPv4
addresses
of
each
LDAP
server.
4.
You
may
change
the
default
TCP
port
number
used
to
listen
to
LDAPS
(optional).
The
well
‐
known
port
for
LDAP
is
636.
5.
Configure
the
Security
Mode:
where:
CN 4093(config)#
ldap-server enable
CN 4093(config)#
ldap-server mode enhanced
CN 4093(config)#
ldap-server host {1-4}
<IP
address
or
hostname>
CN 4093(config)#
ldap-server port
<1
‐
65000>
CN 4093(config)#
ldap-server security {clear|ldaps|mutual|starttls}
Parameter
Description
clear
Cleartext
Mode
(no
security)
ldaps
LDAPS
Mode
mutual
Mutual
authentication
in
Transport
Layer
Security
(TLS)
starttls
Secure
LDAP
via
StartTLS
without
cleartext
fallback
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...