688
Field descriptions
Assets field descriptions
LDAP Properties—Search Parameters tab
Use the Search Parameters tab to specify the location within the LDAP directory hierarchy where
searches begin.
Associated tasks
The task that you can perform with this tab is:
■
“Lightweight Directory Access Protocol (LDAP) authentication”
LDAP Properties—Schema tab
Use the Schema tab to define the types of objects that an LDAP directory can contain.
Associated tasks
The task that you can perform with this tab is:
■
“Lightweight Directory Access Protocol (LDAP) authentication”
Table D-142
LDAP Properties—Search Parameters tab
Field
Description
Base DN (search root)
Distinguished Name (DN) where searches of the LDAP hierarchy begin. This is
typically the Organizational Distinguished Name, which is generally the top or
root of the hierarchy.
Search filter
Filter used to eliminate unwanted information.
Group membership information
used in queries
Select one of the following:
■
User DN
Specifies the more traditional approach whereby group memberships are
determined using the attributes found within LDAP group records. Using
this approach, the DN returned during the authentication process is used
in conjunction with the values specified in the Group Object Class,
Primary Group Attribute, and Group Member Attribute text boxes to
determine user group memberships.
This default option is User DN.
■
User ID attribute
An alternative to the traditional User DN approach. Rather than using
LDAP group records to determine user group memberships, pseudo user
groups are created (implied) by specifying an attribute found within user
records, such as the location attribute (l) or the organizational unit
attribute (ou). With this approach, group records do not actually exist in
the LDAP database, but rather users are implicitly grouped according to
attribute values listed within their user records. By specifying a User ID
Attribute, content is protected and users are granted access based upon
such attributes as location (Boston) or organizational unit (accounting) as
specified within their user record.
Table D-143
LDAP Properties—Schema tab
Field
Description
Use standard LDAPv3 person class The use of this class with LDAP is described in RFC2256, which is part of the
description of LDAP v.3.
This option is checked by default.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...