ShoreTel 4500 Installation Manual page 46

Vpn concentrator
Table of Contents

Advertisement

Configuring the VPN Concentrator
4.1.5.2
Configuring LDAP Settings for Stunnel
An LDAP server is optionally used to store Username/Passwords. This section allows you to
configure various LDAP settings for Stunnel.
Figure 4-12 LDAP Configuration Section of the Stunnel Configuration Page
Parameter
LDAP Authentication
Enable
LDAP Search Base String
LDAP Server IP Address
LDAP Server Port Number
LDAP Server Timeout
4.1.5.3
Configuring a Stunnel IP Address Pool
The Stunnel IP address pool specifies the number of IP addresses which can be assigned to
the peer PPP interface for the incoming Stunnel client session. Specify a valid IP address or
a range of IP addresses, for example: 10.10.10.2 or 10.10.10.2-100. Overlapping IP address
ranges are not supported. The IP Address Pool must be on the same subnet as the VPN
Concentrator. Care must be taken to isolate the peer IP Address Pool from the configured
Server IP address. It is important to remember that every incoming session requires a
unique IP address to be assigned from the Stunnel IP Pool. If the numbers of addresses in
the Pool are not adequate, it imposes a limitation on the maximum number of
40
Description
Enable or disable the LDAP authentication feature to
authenticate the username and password of the SSL VPN
client. A valid LDAP Server IP Address must be configured
to enable this feature. By default LDAP authentication is
disabled.
Enter the base Domain Name of the Active Directory tree
containing the user data. The default string is
"CN=Users,DC=domain,DC=com" which is provided as
an example only. Change the base string to match the
Domain Name of currently used Active Directory tree.
Specify the LDAP Server IP Address. This field is empty by
default. A valid LDAP Server IP is mandatory in order to
enable LDAP Authentication.
Enter the TCP port number of the LDAP Server. The
permissible range of this parameter is 1025-65535, but the
default value of Server port is 389.
Specify the LDAP search timeout. If the LDAP server
doesn't respond within the specified time, the SSL VPN
client' s request is rejected.
Chapter 4

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

45505300lf5300lf2

Table of Contents