6-46
Configuration Options
6.8.7. LDAP Parameters
The VMR/NPS supports LDAP (Lightweight Directory Access Protocol,) which allows
authentication via the "Active Directory" network Directory Service. When LDAP is
enabled and properly configured, command access rights can be granted to new users
without the need to define individual new accounts at each VMR/NPS unit, and existing
users can also be removed without the need to delete the account from each VMR/NPS
unit. This type of authentication also allows administrators to assign users to LDAP
groups, and then specify which plugs the members of each group will be allowed to
control at each VMR/NPS unit.
In order to apply the LDAP feature, you must first define User Names and associated
Passwords and group membership via your LDAP server, and then access the
VMR/NPS command mode to configure LDAP settings and define port access rights
and command access rights for each group specified at the LDAP server.
Notes:
• Plug access rights are not defined at the LDAP server. They are defined via
the LDAP Group configuration menu on each VMR/NPS unit and are specific
to that VMR/NPS unit alone.
• When LDAP is enabled, LDAP authentication will supersede any passwords
and access rights that have been defined via the VMR/NPS user directory.
• If no LDAP groups are defined on a given VMR/NPS unit, then access rights
will be determined as specified by the "default" LDAP group.
• The "default" LDAP group cannot be deleted.
The LDAP Parameters Menu allows you to define the following parameters:
•
Enable:
Enables/disables LDAP authentication. (Default = Off)
•
Primary Host IPv4:
Defines the IP address or domain name for the primary LDAP
server when IPv4 protocol is used to communicate with the VMR/NPS unit.
(Default = undefined)
•
Primary Host IPv6:
Defines the IP address or domain name for the primary LDAP
server when IPv6 protocol is used to communicate with the VMR/NPS unit.
(Default = undefined)
•
Secondary Host IPv4:
Defines the IP address or domain name for the secondary
(fallback) LDAP server when IPv4 protocol is used. (Default = undefined)
•
Secondary Host IPv6:
Defines the IP address or domain name for the secondary
(fallback) LDAP server when IPv6 protocol is used. (Default = undefined)
•
LDAP Port:
Defines the port that will be used to communicate with the LDAP
server. (Default = 389)
•
TLS/SSL:
Enables/Disables TLS/SSL encryption. Note that when TLS/SSL
encryption is enabled, the LDAP Port should be set to 636. (Default = Off)
•
Bind Type:
Sets the LDAP bind request password type. In the Text Interface, when
the Bind Type is set to "Kerberos," the LDAP menu will include an additional prompt
used to select Kerberos parameters. (Default = Simple)