
Switch Security 6 - 97
4. Select LDAP Group Verification Details checkbox. Refer to the
LDAP Server Details
field to define the primary and
secondary Radius LDAP server configuration providing access to an external database used with the local Radius
server.
5. Enable the
Enable Primary Ldap Agent
checkbox to support the PEAP-MSCHAPv2 authentication system with user/
password database as Active Directory.
NOTE:
EAP-TLS will not work with a default trustpoint. Proper CA and Server trustpoints
must be configured for EAP-TLS. For information on configuring certificates for the switch,
see
Creating Server Certificates on page 6-105
.
IP Address
Enter the IP address of the external LDAP server acting as the data source for the Radius server.
This server must be accessible from an active switch subnet.
Port
Enter the TCP/IP port number for the LDAP server acting as the data source.
Password Attribute
Enter the password attribute used by the LDAP server for authentication.
Bind DN
Specify the distinguished name to bind with the LDAP server.
Bind Password
Enter a valid password for the LDAP server.
Base DN
Specify a distinguished name that establishes the base object for the search. The base object is
the point in the LDAP tree at which to start searching.
User Login Filter
Enter the login used by the LDAP server for authentication.
Group Filter
Specify the group filters used by the LDAP server.
Group Membership
Attribute
Specify the Group Member Attribute sent to the LDAP server when authenticating users.
Group Attribute
Specify the group attribute used by the LDAP server.
Net Timeout
Enter a timeout value (between 1-10 seconds) the system uses to terminate the connection to the
Radius Server if no activity is detected.
Domain Name
Enter the Active Directory domain name.
e.g. MotorolaAD.com
Domain Admin
User
Enter the Administrator Username of the LDAP server
Domain Admin
Password
Enter the Administrator User password
LDAP Agent Retry
Timeout
Defines the time interval after which the LDAP Agent will try to reconnect with the LDAP server
if the previous join attempt had failed.
LDAP Server Dead
Period
This is a period in seconds for which the RADIUS server does not attempt any connection with
the LDAP server after the LDAP server was found to be unavailable.
NOTE:
Administrator Username and Administrator User password are required for the
switch (which runs radius server) to become part of the Windows domain of which the
Active Directory Server is part of.
Содержание WiNG 4.4
Страница 1: ...Motorola Solutions WiNG 4 4 SYSTEM REFERENCE GUIDE ...
Страница 2: ......
Страница 3: ...MOTOROLA SOLUTIONS WING 4 4 SYSTEM REFERENCE GUIDE 72E 157062 01 Revision A January 2012 ...
Страница 6: ...iv WiNG 4 4 Switch System Reference Guide ...
Страница 14: ...xii WiNG 4 4 Switch System Reference Guide ...
Страница 48: ...1 32 WiNG 4 4 Switch System Reference Guide ...
Страница 58: ...2 10 WiNG 4 4 Switch System Reference Guide ...
Страница 117: ...Network Setup 4 13 7 Click Cancel to close the dialog without committing updates to the running configuration ...
Страница 280: ...4 176 WiNG 4 4 Switch System Reference Guide ...
Страница 352: ...5 72 WiNG 4 4 Switch System Reference Guide ...
Страница 476: ...6 124 WiNG 4 4 Switch System Reference Guide ...
Страница 506: ...7 30 WiNG 4 4 Switch System Reference Guide ...
Страница 532: ...8 26 WiNG 4 4 Switch System Reference Guide ...
Страница 536: ...A 4 WiNG 4 4 Switch System Reference Guide ...
Страница 544: ...B 12 WiNG 4 4 Switch System Reference Guide ...
Страница 558: ...B 26 WiNG 4 4 Switch System Reference Guide ...
Страница 574: ...C 16 WiNG 4 4 Switch System Reference Guide ...
Страница 596: ...E 4 WiNG 4 4 Switch System Reference Guide ...
Страница 597: ......