CHAPTER 16 Services
Mediant 4000 SBC | User's Manual
■
Search base object (distinguished name or DN, e.g., "ou=ABC,dc=corp,dc=abc,dc=com"),
which defines the location in the directory from which the LDAP search begins. This is
configured in
Configuring LDAP DNs (Base Paths) per LDAP Server
.
■
Filter (e.g., "(&(objectClass=person)(sAMAccountName=johnd))"), which filters the search in
the subtree to include only the login username (and excludes others). For configuration, see
Configuring the LDAP Search Filter Attribute
■
Attribute (e.g., "memberOf") to return from objects that match the filter criteria. This attribute is
configured by the 'Management Attribute' parameter in the LDAP Servers table.
The LDAP response includes all the groups of which the specific user is a member, for example:
CN=\# Support Dept,OU=R&D Groups,OU-
U=Groups,OU=APC,OU=Japan,OU=ABC,DC=corp,DC=abc,DC=com
CN=\#AllCellular,OU=Groups,OU=APC,OU=Japan,OU=ABC,DC=corp,DC=abc,DC=com
The device searches this LDAP response for the group names that you configured in the
Management LDAP Groups table in order to determine the user's access level. If the device finds a
group name, the user is assigned the corresponding access level and login is permitted; otherwise,
login is denied. Once the LDAP response has been received (success or failure), the LDAP session
terminates.
The following procedure describes how to configure an access level per management groups
through the Web interface. You can also configure it through ini file [MgmntLDAPGroups] or CLI
(
configure system > ldap mgmt-ldap-groups
).
➢
To configure management groups and corresponding access level:
1.
Open the LDAP Servers table (
Setup
menu >
IP Network
tab >
RADIUS & LDAP
folder >
LDAP Servers
).
2.
In the table, select the row of the LDAP server for which you want to configure management
groups with a corresponding access level, and then click the
Management LDAP Groups
link
located below the table; the Management LDAP Groups table opens.
3.
Click
New
; the following dialog box appears:
4.
Configure a group name(s) with a corresponding access level according to the parameters
described in the table below.
5.
Click
Apply
, and then save your settings to flash memory.
Table 16-11:Management LDAP Groups Table Parameter Descriptions
Parameter
Description
'Index'
[MgmntLDAPGroups_
GroupIndex]
Defines an index number for the new table row.
Note:
Each row must be configured with a unique index.
'Level'
Defines the access level of the group(s).
- 227 -
Содержание Mediant 4000 SBC
Страница 1: ...User s Manual AudioCodes Series of Session Border Controllers SBC Mediant 4000 SBC Version 7 2...
Страница 40: ...Part I Getting Started with Initial Connectivity...
Страница 48: ...Part II Management Tools...
Страница 113: ...Part III General System Settings...
Страница 118: ...Part IV General VoIP Configuration...
Страница 525: ...Part V Session Border Controller Application...
Страница 654: ...Part VI Cloud Resilience Package...
Страница 663: ...Part VII High Availability System...
Страница 685: ...Part VIII Maintenance...
Страница 759: ...Part IX Status Performance Monitoring and Reporting...
Страница 844: ...Part X Diagnostics...
Страница 888: ...Part XI Appendix...
Страница 1036: ...This page is intentionally left blank CHAPTER 62 Technical Specifications Mediant 4000 SBC User s Manual 1003...