256
Limiting user access
Authenticating with an external authentication server
4
On the Search Parameters tab, do the following:
5
On the Schema tab, do the following:
6
On the Bind tab, to bind using the distinguished name and password, check
Authenticate to server
using Distinguished Name (DN) and password
.
7
Optionally, on the Description tab, type a more detailed description than you typed in the Caption
text box.
8
Click
OK
.
9
Optionally, do one of the following:
■
To save your configuration now, and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
10
After defining the LDAP authentication server, you can use it in the following ways:
■
Identify the server to be used for authentication in an authentication scheme.
■
Use the server as the authentication server in a clientless VPN role.
Related information
For further information related to this topic, see the following:
■
■
“LDAP Properties—Search Parameters tab”
■
■
■
“LDAP Properties—Description tab”
■
“Configuring an authentication scheme”
■
“Creating and assigning roles”
Base DN (search root)
Type the Distinguished Name where searches of the LDAP hierarchy begin.
Search filter
Type the filter to use as a search criteria.
User DN
Check this button to enable the User DN attribute.
User ID Attribute
Check this button to enable User ID attribute.
Use standard LDAPv3 person class Check this box to use the standard LDAP V3 person class.
User object class
Type the name of the object class within the schema that defines user
and user record attributes.
User ID attribute
Type the attribute within an object class that will be used by the LDAP
Ticket Agent to locate user records within the LDAP database.
Group object class
Type the name of the object class within the schema whose attributes
define user groups, group names, and group memberships.
Primary group attribute
Type the attribute within the group object class that identifies the name
of the group.
Group member attribute
Type the attribute the LDAP Ticket Agent uses to retrieve user group
membership information from within the LDAP database.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...