NETGEAR STM150 Appliance Reference Manual page 172

Prosecure web/email security threat management (stm)
Hide thumbs Also See for STM150:
Table of Contents

Advertisement

ProSecure Web/Email Security Threat Management (STM) Appliance Reference Manual
Table 5-5. LDAP Settings (continued)
Setting
Description
Search Base
The distinguished name (dn) at which to start the search, specified as a sequence of
relative distinguished names (rdn), connected with commas and without any blank
spaces. For most users, the search base is a variation of the domain name. For
example, if your domain is yourcompany.com, your search base dn might be as
follows: dc=yourcompany,dc=com.
UID Attribute
The attribute in the LDAP directory that contains the user's identifier (uid).
For an Active Directory, enter sAMAccountName.
For an OpenLDAP directory, enter uid.
Member Groups
The attribute that is used to identify the groups an entry belongs to.
Attribute
For an Active Directory, enter memberOf.
For OpenLDAPy, you can enter a customized attribute to identify the the groups of an
entry.
Note: Do not leave this field blank.
screen.>>
Group Members
The attribute that is used to identify the members of a group.
Attribute
For an Active Directory, enter: member
For OpenLDAPy, you can enter a customized attribute to identify the members of a
group.
Note: Do not leave this field blank.
screen.>>
Additional Filter
This field is optional. A filter that is used when searching the LDAP server for
matching entries while excluding others. Use the format described by RFC 2254.
The following example search terms will match users only:
Active Directory: objectClass=user
Open LDAP: objectClass=posixAccount
3. Click Test to verify that the LDAP server will actually function with the LDAP settings that
you have specified. The automated test procedure checks the connection to the LDAP server;
the bind DN, and the bind password. If any settings require changes, you are notified at the end
of the automated test procedure.
Note: If the automated test procedure returns the message "LDAP server test passed
but size limit exceeded," only a limited number of entries (for example, 1000)
was returned after the LDAP server was queried. To ensure that the lookup
results include all users and groups, set larger values in the LDAP server.
Another workaround is to use a specific search name or a name with a
wildcard in the lookup process, so that the subset of the entire list is returned
in the lookup result.
5-18
<<Reviewers: field still states 'optional' on LDAP
<<Reviewers: field still states 'optional' on LDAP
Managing Users, Groups, and Authentication
v1.0, September 2009

Advertisement

Table of Contents
loading

This manual is also suitable for:

Stm300Stm600

Table of Contents