
5-47
Basic Configuration
5.9.8. LDAP Parameters
The RSM-8R supports LDAP (Lightweight Directory Access Protocol,) which allows
authentication via the "Active Directory" network Directory Service. When LDAP is
enabled and properly configured, command access rights can be granted to new users
without the need to define individual new accounts at each RSM-8R unit, and existing
users can also be removed without the need to delete the account from each
RSM-8R unit.
This type of authentication also allows administrators to assign users to LDAP groups,
and then specify which plugs the members of each group will be allowed to control at
each RSM-8R unit.
In order to apply the LDAP feature, you must first define User Names and associated
Passwords and group membership via your LDAP server, and then access the
RSM-8R command mode to enable and configure the LDAP settings and define port
access rights and command access rights for each group that you have specified at the
LDAP server.
To access the LDAP Parameters menu, login to RSM-8R command mode using a
password that permits Administrator level commands. In the Text Interface, the LDAP
Parameters menu is accessed via the Network Configuration menu. In the Web Browser
Interface, the LDAP Parameters menu is accessed via the flyout menus under the
Network Configuration link.
Notes:
• Port and Plug access rights are not defined at the LDAP server. They are
defined via the LDAP Group configuration menu on each RSM-8R unit and
are specific to that RSM-8R unit alone.
• When LDAP is enabled and properly configured, LDAP authentication will
supersede any passwords and access rights that have been defined via the
RSM-8R user directory.
• If no LDAP groups are defined on a given RSM-8R unit, then access rights
will be determined as specified by the "default" LDAP group.
• The "default" LDAP group cannot be deleted.
The LDAP Parameters Menu allows the following parameters to be defined:
•
Enable:
Enables/disables LDAP authentication. (Default = Off.)
•
Primary Host:
Defines the IP address or domain name (up to 64 characters) for
the primary LDAP server. (Default = undefined.)
•
Secondary Host:
Defines the IP address or domain name (up to 64 characters) for
the secondary (fallback) LDAP server. (Default = undefined.)
•
LDAP Port:
Defines the port that will be used to communicate with the LDAP
server. (Default = 389.)
•
TLS/SSL:
Enables/Disables TLS/SSL encryption. Note that when TLS/SSL
encryption is enabled, the LDAP Port should be set to 636. (Default = Off.)