Ldap Function - Fujitsu PRIMERGY 10/40GbE Connection Blade 18/8+2 Function Manual

Table of Contents

Advertisement

2.31 LDAP Function

LDAP function manages the AAA (Authentication, Authorization, Accounting) information by using the external
server (LDAP server). If the same AAA information is required in many devices or if the large amount of user
information is to be managed then the authentication information is summarized and managed.
In this device, the user authentication function of LDAP client function is supported.
User authentication function executes the authentication process at the time when access user is logged in to
this device.
LDAP client function enables the backup configuration and load sharing configuration used by LDAP server of
multiple machines.
The meaning of each status is as follows.
▪ alive state
It is a status wherein the server is available.
It is used in preference of the higher (numerical value in the definition is small) priority server.
When multiple servers of the same priority exist, the server is selected randomly.
・dead state
It is a status wherein the usage of server stops temporarily due to TCP connection failure of server or when
request of server is timeout. Additionally, when server of 'alive' status exists, defined priority value is not used.
When the time specified in restoration standby time is elapsed, it automatically restores in 'alive' status. At the
time of authentication, if all servers will be in dead status, take the trial in any one of randomly selected server
and the server from which the response is received is restored to alive status.
Points to be noted
▪ RADIUS client function and TACACS+ client function cannot be used simultaneously. When RADIUS client
function (aaa radius) or TACACS+ client function (aaa tacacsp) or LDAP client function is defined in AAA group,
LDAP client function becomes disabled. When LDAP client function and user information (aaa user) both are
defined in AAA group, authentication is executed in the LDAP client function. Even if authentication is failed
in the LDAP client function, user information is not authenticated.
Page 66 of 71

Advertisement

Table of Contents
loading

Table of Contents