
SANGFOR IAM v2.1 User Manual
171
If the authentication does not have the IAM gateway device get involved, SSO is available
only when a listening port is configured first. As to the configuration of a listening port, please
refer to Section 7.2.2.5 SNMP Option.
7.2.2.5.
Listening Mirror Port
Listening mirror port functions when the authentication does not have the IAM gateway device get
involved. The interface (mirror port of the switch) listens to the authentication information
intercepted over the network, which helps to achieve single sign-on.
Check [If login data does not go through the device, please set listening mirror port (which should
be idle)] and select an idle network interface that will act as the listening port.
The listening port must be a port that is not being used by the IAM gateway device.
The mirror port (of the switch) must mirror at least the network interface of the
authentication server.
7.2.2.6.
Only Allow SSO
[Users belonging to following network segment must use SSO (but users that require DKEY or no
authentication are excepted)]: Configures the IP ranges of some LAN user(s) who can only (must)
log in with SSO.
The configuration page is as shown below:
Содержание IAM 2.1
Страница 1: ...SANGFOR IAM v2 1 User Manual IAM 2 1 User Manual September 2010...
Страница 296: ...SANGFOR IAM v2 1 User Manual 295...