Configuring an Identity Server
25
n
ov
do
cx (e
n)
16
Ap
ril 20
10
Level Four Switch Port Translation:
Configure the L4 switch to translate the port of the
incoming request to a new port when the request is sent to a cluster member. Because the
cluster members communicate with each other over the same IP address/port as the L4 switch,
the cluster implementation needs to know what that port is. The translated port is the port on
the cluster members where other cluster members can contact it. This is the IP address and port
where cluster members provide proxy requests to other cluster members.
Port translation is enabled on switch:
Specify whether the port of the L4 switch is
different from the port of the cluster member. For example, enable this option when the L4
switch is using port 443 and the Identity Server is using port 8443.
Cluster member translated port:
Specify the port of the cluster member.
IDP Failover Peer Server Count:
For configuration information, see
Section 1.1.4,
“Configuring Session Failover,” on page 22
.
5
Click
OK
, then update the Identity Server as prompted.
1.1.6 Removing a Server from a Cluster Configuration
Removing an Identity Server from a configuration disassociates the Identity Server from the cluster
configuration. The configuration, however, remains intact and can be reassigned later or assigned to
another server.
1
In the Administration Console, click
Devices > Identity Servers
.
2
Select the server, then click
Stop
. Wait for the Health indicator to turn red.
3
Select the server, then choose
Actions > Remove from Cluster
.
For information about deleting an Identity Server, see
Section 14.1, “Managing an Identity Server,”
on page 317
.
1.1.7 Enabling and Disabling Protocols
You can control which protocols can be used for authenticating with an Identity Server
configuration. A protocol must be enabled and configured before users can use the protocol for
authentication. For tight security, consider disabling the protocols that you are not going to use for
authentication.
When you disable a protocol, updating the Identity Server configuration is not enough. You must
stop and start the Identity Server.
1
In the Administration Console, click
Devices > Identity Servers
>
Edit
.
2
In the
Enabled Protocols
section, select the protocols to enable
3
To disable a protocol, deselect it.
4
Click
OK
.
5
(Conditional) If you have enabled a protocol, update the Identity Server.
6
(Conditional) If you have disabled a protocol, stop and start the Identity Server.
6a
Select the Identity Server, then click
Stop
.
6b
When the health turns red, select the Identity Server, then click
Start
.
6c
Repeat the process for each Identity Server in the cluster.
Summary of Contents for ACCESS MANAGER 3.1 SP2 - README 2010
Page 4: ...4 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 12: ...12 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 158: ...158 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 172: ...172 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 182: ...182 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 290: ...290 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 362: ...362 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...
Page 374: ...374 Novell Access Manager 3 1 SP2 Identity Server Guide novdocx en 16 April 2010...