![ZyXEL Communications SBG5500-A User Manual Download Page 156](http://html1.mh-extra.com/html/zyxel-communications/sbg5500-a/sbg5500-a_user-manual_944297156.webp)
Chapter 9 Firewall
SBG5500 Series User’s Guide
156
The following table describes the labels in this screen.
Table 66 LDAP Server: Add/Edit
LABEL
DESCRIPTION
General Settings
Name
Enter a descriptive name for identification purposes. It cannot exceed 64 characters
[0-9][A-Z] [a-z][_-].
Description
Enter the description of each server, if any. You can use up to 128 printable ASCII
characters.
Server Settings
Server Address
Enter an IP address or Fully-Qualified Domain Name (FQDN) of the LDAP
authentication server.
Backup Server Address
If the LDAP server has a backup authentication server, enter its IP address or FQDN
here.
Port
Specify the port number on the LDAP server to which the SBG sends authentication
requests. Enter a number between 1 and 65535.
Base DN
Specify the directory (up to 127 alphanumerical characters). For example, o=Zyxel,
c=US.
This is only for
LDAP
.
Use SSL
Select
Use SSL
to establish a secure connection to the LDAP server(s).
Search time limit
Specify the timeout period (between 1 and 300 seconds) before the SBG
disconnects from the LDAP server. In this case, user authentication fails.
Search timeout occurs when either the user information is not in the LDAP server(s) or
the LDAP server(s) is down.
Case-sensitive User Names
Select this if the server checks the case of the user names.
Server Authentication
Bind DN
Specify the bind DN for logging into the LDAP server. Enter up to 127 alphanumerical
characters.
For example, cn=zyxelAdmin specifies zyxelAdmin as the user name.
Password
If required, enter the password (up to 15 alphanumerical characters) for the SBG to
bind (or log in) to the AD or LDAP server.
Retype to Confirm
Retype your new password for confirmation.
User Login Settings
Login Name Attribute
Enter the type of identifier the users are to use to log in. For example “name” or “e-
mail address”.
Alternative Login Name
Attribute
If there is a second type of identifier that the users can use to log in, enter it here. For
example “name” or “e-mail address”.
Group Membership
Attribute
An LDAP server defines attributes for its accounts. Enter the name of the attribute
that the SBG is to check to determine to which group a user belongs. The value for
this attribute is called a group identifier; it determines to which group a user belongs.
You can add
ext-group-user
objects to identify groups based on these group
identifier values.
For example you could have an attribute named “memberOf” with values like
“sales”, “RD”, and “management”. Then you could also create a
ext-group-user
object for each group. One with “sales” as the group identifier, another for “RD” and
a third for “management”.
OK
Click
OK
to save your changes.
Cancel
Click
Cancel
to exit this screen without saving.
Summary of Contents for SBG5500-A
Page 12: ...12 PART I User s Guide...
Page 44: ...44 PART II Technical Reference...