Configuring The Ldap Search Filter Attribute - AudioCodes Mediant 1000B User Manual

Analog & digital voip media gateway enterprise session border controller gateway & e-sbc
Hide thumbs Also See for Mediant 1000B:
Table of Contents

Advertisement

User's Manual
Parameter
Index
CLI: set internal-index
[LdapServersSearchD
Ns_Index]
Base Path
CLI: set base-path
[LdapServersSearchD
Ns_Base_Path]

15.3.5 Configuring the LDAP Search Filter Attribute

When the LDAP-based login username-password authentication succeeds, the device
searches the LDAP server for all groups of which the user is a member. The LDAP query is
based on the following LDAP data structure:
Search base object (distinguished name or DN, e.g.,
"ou=ABC,dc=corp,dc=abc,dc=com"): The DN defines the location in the directory
from which the LDAP search begins and is configured in 'Configuring LDAP DNs
(Base Paths) per LDAP Server' on page 208.
Filter (e.g., "(&(objectClass=person)(sAMAccountName=johnd))"): This filters the
search in the subtree to include only the login username (and excludes others). This is
configured by the 'LDAP Authentication Filter' parameter, as described in the following
procedure. You can use the dollar ($) sign to represent the username. For example,
the filter can be configured as "(sAMAccountName=$)", where if the user attempts to
log in with the username "SueM", the LDAP search is done only for the attribute
sAMAccountName that equals "SueM".
Attribute (e.g., "memberOf") to return from objects that match the filter criteria:
The attribute is configured by the 'Management Attribute' parameter in the LDAP
Configuration table (see 'Configuring LDAP Servers' on page 205).
Therefore, the LDAP response includes only the groups of which the specific user is a
member.
Notes:
The search filter is applicable only to LDAP-based login authentication and
authorization queries.
The search filter is a global setting that applies to all LDAP-based login
authentication and authorization queries, across all configured LDAP servers.
Version 6.8
LDAP Search DN Table Parameter Descriptions
Defines an index number for the new table record.
Note: Each table row must be configured with a unique index.
Defines the full path (DN) to the objects in the AD where the query is
done.
The valid value is a string of up to 256 characters.
For example: OU=NY,DC=OCSR2,DC=local. In this example, the DN
path is defined by the LDAP names, OU (organizational unit) and DC
(domain component).
Description
209
Mediant 1000B Gateway & SBC
15. Services

Advertisement

Table of Contents
loading

Table of Contents