CHAPTER 16 Services
Mediant 4000 SBC | User's Manual
●
The search filter is applicable only to LDAP-based login authentication and
authorization queries.
●
The search filter is a global setting that applies to all LDAP-based login
authentication and authorization queries, across all configured LDAP servers.
➢
To configure the LDAP search filter for management users:
1.
Open the LDAP Settings page (
Setup
menu >
IP Network
tab >
RADIUS & LDAP
folder >
LDAP Settings
).
2.
In the 'LDAP Authentication Filter' field, enter the LDAP search filter attribute for searching the
login username for user authentication:
3.
Click
Apply
.
Configuring Access Level per Management Groups Attributes
The Management LDAP Groups table lets you configure LDAP group objects and their
corresponding management user access level. The table is a "child" of the LDAP Servers table
(see
) and configuration is done per LDAP server. For each LDAP
server, you can configure up to three table row entries of LDAP group(s) and their corresponding
access level.
●
The Management LDAP Groups table is applicable only to LDAP-based login
authentication and authorization queries.
●
If the LDAP response received by the device includes multiple groups of which the
user is a member and you have configured different access levels for some of
these groups, the device assigns the user the highest access level. For example, if
the user is a member of two groups where one has access level "Monitor" and the
other "Administrator", the device assigns the user the "Administrator" access level.
●
When the access level is unknown, the device assigns the default access level to
the user, configured by the 'Default Access Level' parameter as used also for
RADIUS (see
Configuring RADIUS-based User Authentication
). This can occur in
the following scenarios:
✔
The user is not a member of any LDAP group.
✔
The group of which the user is a member is not configured on the device (as
described in this section).
✔
The device is not configured to query the LDAP server for a management
attribute (see
).
Group objects represent groups in the LDAP server of which the user is a member. The access
level represents the user account's permissions and rights in the device's management interface
(e.g., Web and CLI). The access level can either be Monitor, Administrator, or Security
Administrator. For an explanation on the privileges of each level, see
When the username- password authentication with the LDAP server succeeds, the device
searches the LDAP server for all groups of which the user is a member. The LDAP query is based
on the following LDAP data structure:
- 226 -
Содержание Mediant 4000 SBC
Страница 1: ...User s Manual AudioCodes Series of Session Border Controllers SBC Mediant 4000 SBC Version 7 2...
Страница 40: ...Part I Getting Started with Initial Connectivity...
Страница 48: ...Part II Management Tools...
Страница 113: ...Part III General System Settings...
Страница 118: ...Part IV General VoIP Configuration...
Страница 525: ...Part V Session Border Controller Application...
Страница 654: ...Part VI Cloud Resilience Package...
Страница 663: ...Part VII High Availability System...
Страница 685: ...Part VIII Maintenance...
Страница 759: ...Part IX Status Performance Monitoring and Reporting...
Страница 844: ...Part X Diagnostics...
Страница 888: ...Part XI Appendix...
Страница 1036: ...This page is intentionally left blank CHAPTER 62 Technical Specifications Mediant 4000 SBC User s Manual 1003...