530
NE2552E Application Guide for ENOS 8.4
Implementing Secure LDAP (LDAPS)
Lightweight
Directory
Access
Protocol
(LDAP)
is
a
protocol
for
accessing
distributed
directory
information
services
over
a
network.
Lenovo
ENOS
uses
LDAP
for
authentication
and
authorization.
With
an
LDAP
client
enabled,
the
switch
will
authenticate
a
user
and
determine
the
user’s
privilege
level
by
checking
with
one
or
more
directory
servers
instead
of
a
local
database
of
users.
This
prevents
customers
from
having
to
configure
local
user
accounts
on
multiple
switches;
they
can
maintain
a
centralized
directory
instead.
As
part
of
SIOM,
you
can
implement
Secure
Lightweight
Directory
Access
Protocol
(LDAPS)
in
addition
to
standard
LDAP.
Enabling LDAPS
When
the
IOM
is
in
SIOM
mode,
all
LDAP
configurations
are
made
from
the
CMM
and
pushed
to
the
IOM.
When
the
IOM
is
in
LIOM
mode,
the
CLI
can
be
used
to
configure
LDAP
settings.
LDAPS
is
disabled
by
default.
To
enable
LDAPS:
1.
Turn
LDAP
authentication
on
2.
Enable
LDAP
Enhanced
Mode:
This
changes
the
ldap-server
subcommands
to
support
LDAPS.
3.
Configure
the
IPv4
addresses
of
each
LDAP
server.
4.
You
may
change
the
default
TCP
port
number
used
to
listen
to
LDAPS
(optional).
The
well
‐
known
port
for
LDAP
is
636.
5.
Configure
the
Security
Mode:
where:
NE2552E(config)#
ldap-server enable
NE2552E(config)#
ldap-server mode enhanced
NE2552E(config)#
ldap-server host {1-4}
<IP
address
or
hostname>
NE2552E(config)#
ldap-server port
<1
‐
65000>
NE2552E(config)#
ldap-server security {clear|ldaps|mutual|starttls}
Parameter
Description
clear
Cleartext
Mode
(no
security)
ldaps
LDAPS
Mode
mutual
Mutual
authentication
in
Transport
Layer
Security
(TLS)
starttls
Secure
LDAP
via
StartTLS
without
cleartext
fallback
Summary of Contents for ThinkSystem NE2552E
Page 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Page 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Page 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Page 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Page 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Page 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Page 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Page 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Page 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Page 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Page 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Page 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Page 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Page 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Page 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Page 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Page 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Page 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Page 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Page 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Page 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Page 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Page 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Page 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Page 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Page 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Page 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Page 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Page 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Page 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Page 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Page 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Page 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Page 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Page 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Page 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Page 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Page 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Page 573: ......
Page 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...