Dell SonicWALL Secure Mobile Access 8.5
Administration Guide
407
23 On the
General
tab, you can optionally fill out one or multiple
LDAP Attribute
fields with the
appropriate names where
name=value
is the convention for adding a series of LDAP attributes. To see a
full list of LDAP attributes, refer to the
Dell SonicWALL LDAP Attribute document
.
As a common example, fill out an attribute field with the memberOf= attribute which can bundle the
following common variable types:
CN= - the common name. DN= - the distinguished name. DC= - the domain component.
You need to provide quote delimiters around the variables you bundle in the memberOf line. You
separate the variables by commas. An example of the syntax using the
CN
and
DC
variables would be:
memberOf="CN=<string>, DC=<string>"
An example of a line you might enter into the
LDAP Attribute
field, using the
CN
and
DC
variables
would be:
memberOf="CN=Terminal Server Computers,CN=Users,DC=sonicwall,DC=net"
24 Type an inactivity timeout value (in minutes) in the
Inactivity Timeout
field. Enter
0
(zero) to use the
global inactivity timeout setting.
25 Under
Single Sign-On Settings
, in the
Automatically log into bookmarks list
, select one of the
following:
• Use global policy
– Use the global policy for using SSO to log in to bookmarks.
• User-controlled (enabled by default for new users)
– Enable SSO to log in to bookmarks for
new users, and allow users to change this setting.
• User-controlled (disabled by default for new users)
– Disable SSO to log in to bookmarks for
new users, and allow users to change this setting.
• Enabled
– Enable SSO to log in to bookmarks
• Disabled
– Disable SSO to log in to bookmarks
26 Click
Accept
when done.
LDAP Attribute Information
When configuring LDAP attributes, the following information could be helpful:
•
If multiple attributes are defined for a group, all attributes must be met by LDAP users.
•
LDAP authentication binds to the LDAP tree using the same credentials as are supplied for
authentication. When used against Active Directory, this requires that the login credentials provided
match the CN (common name) attribute of the user rather than SMAAccountName (login name). For
example, if your Active Directory login name is
gkam
and your full name is
guitar kam,
when logging