
S W G U s e r G u i d e
Chapter 19: Performing Additional Configuration Tasks
116
4. In the User Identifier Attribute field, specify the attribute that is used to indicate a user’s unique
identifier. The value of this attribute will be compared to the user name provided by the proxy
authentication.
If left blank, users will be identified by their DNs.
5. In the
Attribut
e, specify the attribute that is used to indicate a user’s email.
6. In the
User
Object
Filter
field, define in LDAP query syntax the filter that can be optionally used
to identify user objects.
7. In the
Group
Identifier
Attribute
field, specify the attribute that is used to indicate a group’s
unique identifier. The Management Console will use the value of this attribute when displaying
group names and assigning policies.
If left blank, users will be identified by their DNs.
8. In the
Group
Object
Filters
field, define in LDAP query syntax the filter that will be used to iden‐
tify group objects.
9. In the
Connection
Timeout
field, set the maximum number of seconds for an unanswered LDAP
query, after which, users will not be imported. If set to 0, it will use the system default, which is
120 seconds.
10. In the
Group
User
Hierarchy
Method
area, select how the group‐user relationship is imple‐
mented in the LDAP directory. The attribute types are follows:
• I
memberOf
Attribute
— Means that each user has zero or more memberOf attributes, each
specifying a group to which the user belongs.
•
member
Attribute
— Means that each group has zero or more 'member' attributes, each
specifying a user, or a group, belonging to this group.
11. If
Custom
directory type is used and
member
Attribute
is used as the hierarchy method, there is
an additional checkbox
Use
"User
Identifier"
attribute
value
for
group
user
relationship
.
Usually the
member
attribute
s hold member DNs as a reference. In some LDAP directories,
instead of holding the DN, they hold the value designated by the 'User Identifier' attribute.
Selecting this checkbox enables handling such configurations.
12. To not check the connection to the server, select the
Do
not
check
configuration
settings
on
next
save
checkbox at the bottom of the window.
13. When done, click
Save
.
14. If you already have some LDAP groups/users imported into the system and you have changed
some of the above values except for Connection Timeout:
a. Remove all LDAP groups that were already imported into the system.
b. Right‐click the LDAP directory node in the tree and select
Add
Groups
.
c. After the right pane page is displayed click
Import
LDAP
Groups
. The group LDAP list is
displayed.
d. From LDAP list select the LDAP groups.
e. Import all LDAP users again.
15. After all the LDAP users are imported, and you are ready to distribute and implement the changes
in your system devices, click
.