Dell SonicWall SRA 4200 Administrator's Manual page 157

Sra 6.0
Table of Contents

Advertisement

Do not include quotes ("") in the LDAP BaseDN field.
Note
Enter the common name of a user that has been delegated control of the container that user
Step 6
will be in along with the corresponding password in the Login Username and Login Password
fields.
When entering Login Username and Login Password, remember that the SRA
Note
appliance binds to the LDAP tree with these credentials and users can log in with
their sAMAccountName.
Enter the name of the layout in the Portal Name field. Additional layouts may be defined in the
Step 7
Portals > Portals page.
Optionally select the Allow password changes (if allowed by LDAP server) check box. This
Step 8
option, if allowed by your LDAP server, will enable users to change their LDAP password during
an SRA session.
Optionally select the Use SSL/TLS check box. This option allows for the SSL/TLS encryption
Step 9
to be used for LDAP password exchanges. This option is disabled by default as not all LDAP
servers are configured for SSL/TLS.
Optionally select the Enable client certificate enforcement check box to require the use of
Step 10
client certificates for login. By checking this box, you require the client to present a client
certificate for strong mutual authentication. Two additional fields will appear:
Verify user name matches Common Name (CN) of client certificate - Select this check
box to require that the user's account name match their client certificate.
Verify partial DN in subject - Use the following variables to configure a partial DN that will
match the client certificate:
User name: %USERNAME%
Domain name: %USERDOMAIN%
Active Directory user name: %ADUSERNAME%
Wildcard: %WILDCARD%
Select the Auto-assign groups at login check box to assign users to a group when they log in.
Step 11
Users logging into LDAP domains are automatically assigned in real time to SRA groups based
on their external LDAP attributes. If a user's external group membership has changed, their
SRA group membership automatically changes to match the external group membership.
Optionally select the One-time passwords check box to enable the One Time Password
Step 12
feature. A drop-down list will appear, in which you can select if configured, required for all
users, or using domain name. These are defined as:
if configured - Only users who have a One Time Password email address configured will
use the One Time Password feature.
required for all users - All users must use the One Time Password feature. Users who do
not have a One Time Password email address configured will not be allowed to login.
using domain name - Users in the domain will use the One Time Password feature. One
Time Password emails for all users in the domain will be sent to username@domain.com.
If you selected if configured or required for all users in the One-time passwords drop-down
list, the LDAP e-mail attribute drop-down list will appear, in which you can select mail,
userPrincipalName, or custom. These are defined as:
mail - If your LDAP server is configured to store email addresses using the "mail" attribute,
select mail.
Portals Configuration | 157

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents