background image

52

LDAP Authentication Settings

LDAP Configuration

AP Operation

To allow authentication and authorization for the B051-000 via LDAPS, do the following:

1. Check Enable in the LDAP Authentication Settings section of the ANMS screen.

2. Select either the LDAP or LDAPS radio button.

3. Check the Enable Authorization check box.

4. Fill in the IP address and port number for the LDAP or LDAPS server. For LDAP, the default port number is 389; for LDAPS, the default port 

number is 636.

5. In the Timeout field: Set the time in seconds that the B051-000 waits for an LDAP or LDAPS server reply before it times out.

6. In the LDAP Administrator DN field, set the ‘root’ point for the LDAP manager to bind to the server.

7. In the Search DN field, set the distinguished name of the search base (i.e. the domain name where the search starts for the user name).

8. In the B051-000 Admin Group field, key in the name of the LDAP manager. (This field is optional.)

9. In the LDAP Administrator Password field, key in the LDAP manager’s password. (This field is optional.)

10. On the LDAP server, set the access rights for each user. (See LDAP Configuration below for details on setting up LDAP for use with the 

B051-000.)

Active Directory

To allow authentication and authorization for the B051-000 via LDAP 
or LDAPS, the Active Directory’s LDAP Schema must be extended 
so that an extended attribute name for the B051-000 – permission – is 
added as an optional attribute to the person class.

•  Authentication 

refers to determining the authenticity of the person 

logging in.

•  Authorization 

refers to assigning permission to use the device’s 

various features.

In order to configure the LDAP server, you will have to complete the 

following procedures: 1) Install the Windows 2003 Support Tools; 
2) Install the Active Directory Schema Snap-in; and 3) Extend and 

Update the Active Directory Schema.

Install the Windows 2003 Support Tools

1. On the CD that came with the B051-000, open the Support → Tools 

folder.

2. In the right panel of the dialog box that comes up, double click 

SupTools .msi.

3. Follow along with the Installation Wizard to complete the 

procedure.

Install the Active Directory Schema Snap-in

1. Open a Command prompt.

2. Key in 

regsvr32 schmmgmt.dll 

to register schmmgmt.dll 

on your computer.

3. Open the Start menu. Click Run and key in 

mmc /a

. Click OK.

4. On the File menu of the screen that appears, click Add/Remove 

Snap-in, then click Add.

5. Under Available Standalone Snap-ins, double click Active 

Directory Schema, click Close and click OK.

6. On the screen you are in, open the File menu and click Save.

7. For Save in, specify the C:\Windows\system32 directory.

8. For File name, key in schmmgmt.msc.

9. Click Save to complete the procedure.

Extend and Update the Active Directory Schema

Step 1 - Create a New Attribute:

a) Open Control Panel 

→ 

Administrative Tools 

→ 

Active 

Directory Schema.

b) In the left panel of the screen that comes up, right-click Attributes:

c) Select New 

→ 

Attribute.

d) In the warning message that appears, click Continue to bring up 

the Create New Attribute dialog box.

e) Fill in the dialog box, then click OK to complete Step 1 of the 

procedure.

Содержание B051-000

Страница 1: ...d and used in accordance with the instruction manual may cause harmful interference to radio communications Operation of this equipment in a residential area is likely to cause harmful interference in which case the user will be required to correct the interference at their own expense RoHS This product is RoHS compliant Package Contents The B051 000 package consists of 1 B051 000 IP Remote Access...

Страница 2: ...guration 23 Starting the OpenLDAP Server 23 Customizing the OpenLDAP Schema 24 LDAP DIT Design and LDIF File 24 LDAP Data Structure 24 DIT Creation 24 Using the New Schema 25 Log Server Settings 25 User Management 25 Customization 26 Maintenance 27 The Windows Client 29 Starting Up 29 Navigation 29 Mouse Synchronization Tips 29 Windows 29 Sun Linux 30 The Windows Client Control Panel 31 Hotkey Set...

Страница 3: ...rver 56 Customizing the OpenLDAP Schema 56 LDAP Data Structure 56 DIT Creation 57 Using the New Schema 57 User Management 58 Customization 59 Upgrading the Firmware 60 The AP Java Client 60 Starting Up 60 The Java Client Connection Screen 60 Logging In 60 Appendix 61 Specifications 61 PPP Dial In Modem Operation 61 Troubleshooting 62 Mouse Synchronization Tips 63 Windows 63 Sun Linux 64 Warranty R...

Страница 4: ... low bandwidth operation Allows for full screen or sizable remote desktop window In full screen mode the remote desktop display scales to user s monitor display size Advanced security features include password protection and advanced encryption technologies Secure 128 bit SSL encryption Enable disable browser operation Event logging Remote firmware upgrading It is recommended that the computers us...

Страница 5: ...uters servers that are connected to the B051 000 or are connected to a KVM switch that is connected to the B051 000 are shown Computer servers remotely accessing the B051 000 must have Windows 2000 or higher or an operating system that is capable of running Sun s Java Runtime Environment JRE 6 Update 3 or higher Operating System Version Windows 2000 and higher Linux RedHat 7 1 and higher Linux Fed...

Страница 6: ...or ballpoint pen 3 10 100 Mbps LED This LED lights Orange to indicate a data transmission speed of 10Mbps or Green to indicate a Data transmission speed of 100 Mbps 4 Link LED This LED flashes Green to indicate that the B051 000 is being accessed remotely 5 Power LED This LED lights Orange when the B051 000 is powered on and ready to operate No Component Description 1 Power Jack The included power...

Страница 7: ...ng guidelines Install the power supply before connecting the power cable to the power supply Unplug the power cable before removing the power supply If the system has multiple sources of power disconnect power from the system by unplugging all power cables from the power supplies Never push objects of any kind into or through any openings on the unit They may touch dangerous voltage points or shor...

Страница 8: ...convenience and flexibility the B051 000 comes with a 0U rackmount kit so the unit can be conveniently mounted on a system rack To rack mount the unit do the following 1 Remove the two original screws from the bottom of the unit near the rear of the unit 2 Using the screws and bracket provided with the rack mount kit screw the mounting bracket into the B051 000 as shown in the diagram below DIN Ra...

Страница 9: ...t you are installing Note The diagram shows a connection to a KVM switch with PS 2 mouse and keyboard ports using a PS 2 KVM cable kit 3 If you want to use the Virtual Media function plug the USB 2 0 Virtual Media Cable provided with this package from a computer server s USB port into the B051 000 Virtual Media port Note Virtual Media will not work if the cable is plugged into a USB port on a KVM ...

Страница 10: ...anel consists of three columns as shown in the following table Item Description Model Name The device s model name B051 000 MAC Address The MAC address of the device IP Address The current IP Address of the device 3 Select the B051 000 from the Device List If there is more than one B051 000 use the MAC address to find the unit that you want The MAC address can be located on the bottom of the unit ...

Страница 11: ...Installer file from the CD that came with the B051 000 and follow the step by step instructions The first time you login to the AP Windows Client you will need the serial number located on the CD that came with the B051 000 This is not the same as the serial number on the bottom of the unit When you run the program it searches the network segment for B051 000 devices and displays the results in a ...

Страница 12: ...k Yes to login right away skip to the text following Step 5 of the next section To install the certificate do the following 1 In the Security Alert dialog box click View Certificate The Certificate Information dialog box appears Note There is a red and white X logo over the certificate to indicate that it is not trusted 2 Click Install Certificate 3 Follow the Installation Wizard to complete the i...

Страница 13: ...o logout of the B051 000 Note It is recommended that you logout of every session If you exit the B051 000 without clicking the logout icon you must wait for the logout timeout setting to expire before you can login again See page 27 for logout timeout setting options Administration Icons The icons arranged horizontally across the top of the page are linked to the administration utilities which are...

Страница 14: ...e running a Windows operating system to use the Windows Client Open Java Applet Clicking the Open Java Applet icon will use a Java applet to open the remote display on your desktop Note To use the Java Applet you must have Sun s Java Runtime Environment JRE 6 Update 3 or higher installed on your computer Note If a user does not have permission to access the Java Applet or Windows Client the icon w...

Страница 15: ...51 000 s network environment An explanation of each of the fields is given in the table below Field Explanation Device Name To make it easier to manage installations that have more than one B051 000 each one can be given a name To assign a name for the B051 000 type the desired name in this field 16 characters max MAC Address The B051 000 s MAC address displays here Firmware Version Indicates the ...

Страница 16: ... Obtain an IP address automatically button Note If the B051 000 is on a network that uses DHCP to assign network addresses and you need to ascertain its IP address contact your system administrator To specify a fixed IP address select the Set IP address manually button and fill in the IP address Subnet Mask and Default Gateway that are appropriate for your network The B051 000 can either have its ...

Страница 17: ...e name field will require users to type in 192 168 0 126 abcdefg to access the B051 000 remotely Note If no string is specified here anyone can access the B051 000 with a Web browser using the IP address alone This makes the installation less secure To enable IP and or MAC filtering click the IP Filter Enable and or MAC Filter Enable checkbox There are a maximum of 100 filters allowed for each If ...

Страница 18: ... will be denied access to the B051 000 even if the computer is allowed to access the B051 000 under the MAC Filters that are set up To add a MAC Filter 1 Click Add A dialog box similar to the one below appears 2 Type in the desired MAC address and click OK 3 Repeat these steps for any additional MAC addresses you want to filter To delete a MAC Filter Select the desired MAC Filter from the list and...

Страница 19: ...DAPS Enable Authorization Click on Enable Authorization if you want it enabled 1 If enabled the LDAP LDAPS server directly returns a permission attribute and authorization for the user that is logging in With this selection the LDAP schema must be extended See LDAP Server Configuration page xx for details 2 If not enabled the server returns a result that depends on whether the user that is logging...

Страница 20: ...d 5 Under Available Standalone Snap ins double click Active Directory Schema click Close and click OK 6 On the screen you are in open the File menu and click Save 7 For Save in specify the C Windows system32 directory 8 For File name key in schmmgmt msc 9 Click Save to complete the procedure Create a Start Menu Shortcut Entry To create a shortcut entry on the Start Menu for the Active Directory Sc...

Страница 21: ...at comes up select permission then click OK to complete Step 2 of the procedure Step 3 Edit Active Directory Users With the Extended Schema a Run ADSI Edit Installed as part of the Support Tools b Open domain and navigate to the cn users dc tripplite dc com node c Locate the user you wish to edit Our example uses jason d Right click on the user s name and select properties e On the Attribute Edito...

Страница 22: ...Allows the user to use the Virtual Media function Access rights examples are given in the table below User Value Meaning User1 10 0 0 166 w v 1 User has Windows Client and View Only rights on a B051 000 with an IP address of 10 0 0 166 2 User has no rights on any other B051 000 units administered by the LDAP server User2 10 0 0 164 s 10 0 0 166 j c 1 User has Virtual Media rights on a B051 000 wit...

Страница 23: ...P pid and args start up files The first contains the server pid the second includes command line arguments Choose the database type The default is bdb Berkeley DB Specify the server suffix All entries in the directory will have this suffix which represents the root of the directory tree For example with suffix dc tripplite dc com the fully qualified name of all entries in the database will end wit...

Страница 24: ...below LDAP Data Structure An LDAP directory stores information in a tree structure known as the Directory Information Tree DIT The nodes in the tree are directory entries and each entry contains information in attribute value form An example of the LDAP directory tree for the B051 000 is shown in the figure below The LDAP Data Interchange Format LDIF is used to represent LDAP entries in a simple t...

Страница 25: ... number of different user types You can have 64 administrators 64 users or 64 customized profiles the only limit being you can have no more than 64 in total 3 Restart the LDAP server 4 Write the LDIF file and create the database entries in init ldif with the ldapadd command as shown in the following example ldapadd f init ldif x D cn Manager dc tripplite dc com w secret Adding a User Profile To ad...

Страница 26: ...ly permission This is because Admin users will have full access to all computers servers connected to the B051 000 Clicking on User will give the user access to the Win Client Java Applet and Virtual Media They will have full access to all computers servers connected to the B051 000 Users will not be able to Configure the B051 000 or access the Log Server Clicking on Select allows you to choose wh...

Страница 27: ...USB IO Settings OS When connecting to a computer or KVM switch with the USB connector for keyboard and mouse drop down the list to select the platform it uses Choices are PC Mac1 Mac2 and Sun PC is the default OS Note In general Mac 1 works best with older Mac OS versions whereas Mac 2 works best with newer ones This may vary however If you encounter problems with one setting try selecting the oth...

Страница 28: ...s backup files as B051 000BKUP conf If you want to save more than one backup file simply rename the file to something convenient when you save it Restore Configuration User Accounts Saved Configuration User Accounts information can be restored in the Restore Configuration User Accounts section of the page To restore a previous backup do the following 1 In the Password field key in the same passwor...

Страница 29: ...ou normally would Before trying any mouse synchronization procedures it is always a good idea to ensure that you go to your Mouse Properties Settings and set them according to the following Note In order for the local and remote mice to synchronize you must use the generic mouse driver supplied with the MS operating system If you have a third party driver installed such as one supplied by the mous...

Страница 30: ...eas Mac 2 works best with newer ones This may vary however If you encounter problems with one setting try selecting the other one Adjust Mouse Hotkey The Windows Client Control Panel which is discussed in the following sections contains a Hotkey Alt M by default that syncs the local mouse pointer with the remote mouse pointer Simply press the Alt M Hotkey and the local and remote mouse pointers sh...

Страница 31: ...nection Click to bring up the Virtual Media dialog box The red X indicates that this feature has not been started When in use the icon changes to indicate the type of virtual media device being used Click to open the Message Board Click to send a Ctrl Alt Del signal to the remote system Click on the keyboard to enable the on screen keyboard Click on the drop down arrow to bring up a list of availa...

Страница 32: ...on Adjust the horizontal and vertical position of the remote computer window by clicking the Arrow buttons Auto Sync Click Auto Sync to have the function detect the vertical and horizontal offset values of the remote screen and automatically synchronize it with the local screen If the local and remote mouse pointers are out of sync in most cases performing this function will bring them back into s...

Страница 33: ...ver where it shows up as a drive or folder on the remote server s file system Note You can dismiss the Virtual Media dialog box at this point the redirection will stay in effect You can treat the folder as if it were really on the remote server drag and drop files to from it open files on the remote system for editing and save them to the redirected drive etc Files that you save to the redirected ...

Страница 34: ...your message If a user has disabled chat its icon displays before the user s name to indicate so If a user has occupied the KVM or the KM the corresponding icon displays before the user s name to indicate so Compose Panel Type your message into this panel Click Send or press Enter to post the message to the board Note You must select the user from the user list that you want to send the message to...

Страница 35: ... local and remote programs minimize the Windows Client window and use Alt Tab as you normally would Before trying any mouse synchronization procedures it is always a good idea to ensure that you go to your Mouse Properties Settings and set them according to the following Note In order for the local and remote mice to synchronize you must use the generic mouse driver supplied with the MS operating ...

Страница 36: ...electing the other one Adjust Mouse Hotkey The Java Client Control Panel which is discussed in the following sections contains a Hotkey Alt M by default that syncs the local mouse pointer with the remote mouse pointer Simply press the Alt M Hotkey and the local and remote mouse pointers should sync within a few seconds Auto Sync Button In the Video Settings Menu which is discussed in the following...

Страница 37: ...ayscale and color Click to bring up the Message board Click to send a Ctrl Alt Del signal to the remote system Click on the keyboard to enable the on screen keyboard Click on the drop down arrow to bring up a list of available language keyboards You can choose between English Chinese Taiwan Japanese German French Spanish Korean and Italian Click to exit the remote view These icons show the Num Loc...

Страница 38: ...implement their effects on the remote system a function key is substituted for the Alt key If you substitute the F12 key for example you would use F12 Tab and Ctrl F12 Del F12 Exit remote view Ends the remote connection to the B051 000 and returns to local operation Alt E Configuring the Hotkeys If you find the default Hotkey combinations inconvenient you can configure your own by following these ...

Страница 39: ...To alleviate this problem a message board feature similar to an internet chat program allows users to communicate with each other The buttons on the Button Bar are toggles Their actions are described in the table below Button Function Enable Disable Chat When disabled the icon displays next to the disabled user s name in the User List panel of all users message boards Messages directed to the disa...

Страница 40: ...Korean and Italian Click on the arrow to the right of the icon to display the list of available languages After selecting your language click the icon to bring up the keyboard In the future after having selected the desired language you only need to click the keyboard icon Click this button to exit the Java Applet and return to local operation Ctrl Alt Del Exit Lock LEDs Clicking this button sends...

Страница 41: ...maximum of 512 events are kept in the log file As new events are recorded they are placed at the bottom of the list When a new event is recorded after there are 512 events in the log file the earliest event in the list is discarded To clear the log file click on the Clear Log icon at the lower right of the page Note To maintain and view a record of all the events that take place not just the most ...

Страница 42: ... port number for the computer server that you have installed the Log Server on See page 18 for details Double click the Log Server icon to bring up the Log Server The first time you run it a screen similar to the one below appears Note The Log Server requires the Microsoft Jet OLEDB 4 0 driver in order to access the database The screen is divided into three components A Menu Bar at the top A panel...

Страница 43: ...his specifies the number of days that an event is kept in the Log Server s database before it can be deleted To remove all events that have passed the expiration date set in this field use the Maintenance function in the Events menu Edit Select the Edit function when you need to change the information for an existing B051 000 To edit an existing B051 000 simply select it from the list and open the...

Страница 44: ...ch to start from End Date Select the date that you want the search to end at The format follows the MM DD YYYY convention e g 11 04 2005 End Time Select the time that you want the search to end at Pattern Key in text here that you want the search to filter the events by Results The events that matched your search terms are listed here Search After you have entered in all of your search terms click...

Страница 45: ...dress This is the IP address or DNS name that was given to the B051 000 when it was added to the Log Server Port This is the port number that was assigned to the B051 000 when it was added to the Log Server Connection If the Log Server is connected to the B051 000 this field displays Connected If it is not connected this field displays Waiting This means that the Log Server is not communicating wi...

Страница 46: ... CD that came with the B051 000 Letters in the serial number must be entered in capitals This dialog box only appears the first time you run the program In the future you go directly to the Windows Client connection screen A description of the items in the AP Windows Client connection screen is given in the following table Item Description Server List Each time the B051 000 AP Windows Client progr...

Страница 47: ...on to open a window on your desktop containing the remote server s display This is the same as the one that appears with the browser based Windows Client Refer to Chapter 5 The Windows Client for operational details Change Password Allows users to change their passwords without Administrator intervention Admin Utility The Administrator Utility provides administrators with a non browser based metho...

Страница 48: ... be specified when connecting to the B051 000 from the stand alone AP Windows Client program Valid entries are from 1024 65535 The default is 9000 Virtual Media This is the port number used for data transfer when accessing the B051 000 s Virtual Media feature Valid entries are from 1024 65535 The default is 9003 HTTP The port number for a browser login Valid entries are from 1 65535 The default is...

Страница 49: ...y page is used to control access to the B051 000 To enable IP and or MAC Filtering click the IP Filter Enable and or MAC Filter Enable checkbox There are a maximum of 100 filters allowed for each If the include button is checked all the addresses within the filter range are allowed access to the B051 000 all other addresses are denied access If the exclude button is checked all the addresses withi...

Страница 50: ...pear 2 Delete the old start IP address and replace it with the new one Click OK 3 Delete the old end IP address and replace it with the new one Click OK Note To block a computer from accessing the B051 000 you do not need to filter both its IP address and its MAC address Any computer blocked by an IP Filter will be denied access to the B051 000 even if the computer is allowed to access the B051 00...

Страница 51: ...and the RADIUS Server 6 On the RADIUS server set the access rights for each user according to the information in the table below Character Meaning C Grants the user administrator privileges allowing the user to configure the system W Allows the user to access the system via the Windows Client program J Allows the user to access the system via the Java Applet L Allows the user to access log informa...

Страница 52: ...thentication refers to determining the authenticity of the person logging in Authorization refers to assigning permission to use the device s various features In order to configure the LDAP server you will have to complete the following procedures 1 Install the Windows 2003 Support Tools 2 Install the Active Directory Schema Snap in and 3 Extend and Update the Active Directory Schema Install the W...

Страница 53: ...d fill in the General page of the dialog box according to the example below e Select the Attributes tab and click the Add button f In the list that comes up select permission then click OK to complete Step 2 of the procedure Step 3 Edit Active Directory Users With the Extended Schema a Run ADSI Edit Installed as part of the Support Tools b Open domain and navigate to the cn users dc tripplite dc c...

Страница 54: ...indows Client program J Allows the user to access the system via the Java Applet L Allows the user to access log information via the user s browser V Limits the user s access to only viewing the video display S Allows the user to use the Virtual Media function Access rights examples are given in the table below User Value Meaning User1 10 0 0 166 w v 1 User has Windows Client and View Only rights ...

Страница 55: ...s and install OpenLDAP slapd as NT service as shown in the diagram The main OpenLDAP configuration file slapd conf has to be customized before launching the server The modifications to the configuration file will do the following Specify the Unicode data directory The default is ucdata Choose the required LDAP schemas The core schema is mandatory Configure the path for the OpenLDAP pid and args st...

Страница 56: ... For details about slapd options and their meanings refer to the OpenLDAP documentation The schema that slapd uses may be extended to support additional syntaxes matching rules attribute types and object classes In the case of the B051 000 the B051 000User class and the permission attribute are extended to define a new schema The extended schema file used to authenticate and authorize users loggin...

Страница 57: ...e the new schema do the following 1 Save the new schema file e g B051 000 schema in the OpenLDAP schema directory 2 Add the new schema to the slapd conf file as shown in the figure below The following figure illustrates an LDIF file that defines the OpenLDAP group for the B051 000 3 Restart the LDAP server 4 Write the LDIF file and create the database entries in init ldif with the ldapadd command ...

Страница 58: ...ped in the password correctly you are asked to enter it again If the two entries do not match you will not be allowed to save the changes Description This is an optional field that is used to record any additional information about the user profile Permissions Click on a permission to add or remove access to a particular feature You can choose to assign Admin permissions User permissions or Select...

Страница 59: ...is checked by default Enable Multiuser If this item is checked multiple users can log into the B051 000 at the same time It is checked by default Mouse Sync Mode Automatic If this item is checked the B051 000 will automatically sync the remote and local mouse pointers It is checked by default Note This feature only supports USB mice on Windows and Mac G4 or higher systems For all other configurati...

Страница 60: ...irst time that you are running the program a dialog box appears requesting you to input your serial number To connect to the B051 000 1 Key in its IP address in the Server field 2 Key in the correct port number 3 Click Connect The serial number can be found on the B051 000 s CD case This is not the same as the serial number that is on the bottom of the unit You must use the serial number from the ...

Страница 61: ...he connection has been established open your browser and specify the address 192 168 192 1 From here operation of the B051 000 is the same as if you had accessed it from the ordinary network Note When accessing the B051 000 via PPP Dial In Modem video is automatically forced to grayscale and the Video Quality setting is set at the lowest level Connection Setup Example Windows XP To set up a dial i...

Страница 62: ...ificate is not trusted or a Certificate Error message The certificate can be trusted click on the link that says Continue to this website Not recommended See page 12 for details Part of remote window is off my monitor Use the AutoSync feature to sync the local and remote monitors Virtual Media doesn t work Make sure that the Virtual Media cable is properly connected See page 33 Mac Systems Problem...

Страница 63: ... Mouse Properties Settings and set them according to the following Note In order for the local and remote mice to synchronize you must use the generic mouse driver supplied with the MS operating system If you have a third party driver installed such as one supplied by the mouse manufacturer you must remove it Windows 2000 1 Open the Mouse Properties dialog box Control Panel Mouse Mouse Properties ...

Страница 64: ...tains a Hotkey Alt M by default that syncs the local mouse pointer with the remote mouse pointer Simply press the Alt M Hotkey and the local and remote mouse pointers should sync within a few seconds Auto Sync Button In the Video Settings Menu there is an Auto Sync button that also server to sync the local and remote mouse pointers In most cases performing an Auto Sync will align the two mouse poi...

Страница 65: ...You will be advised of your right to file a complaint with the FCC Your telephone company may make changes in its facilities equipment operations or procedures that could affect the proper operation of your equipment If it does you will be given advance notice to give you an opportunity to maintain uninterrupted service If you experience trouble with this equipment s Modem Fax Protection please ca...

Отзывы: