default value is sAMAccountName=%1, which is correct for use with Active
Directory. This field is required for LDAP searches.
To configure LDAP search parameters:
1.
Select Appliance - Appliance Settings - User Accounts - LDAP Accounts >
Search.
2.
Enter the appropriate information in the Search DN, Search Password,
Search Base and UID Mask fields.
3.
Click Save.
These options cannot be changed if the LDAP Priority is set to LDAP Disabled on the
Overview screen.
LDAP Query parameters
On the LDAP Query page, you can configure the parameters used when
performing user authentication queries.
The appliance performs two different types of queries. Query Mode (Appliance) is
used to authenticate administrators and users attempting to access the appliance
itself. Query Mode (Target Device) is used to authenticate users that are
attempting to access attached target devices. Additionally, each type of query has
three modes that utilize certain types of information to determine whether or not
an LDAP user has access to an appliance or connected target devices. See
"Appliance and target device query modes" on page 71 detailed information on
each mode.
You can configure the following settings on the LDAP Query Page:
•
The Query Mode (Appliance) parameters determine whether or not a user
has access to the appliance.
•
The Query Mode (Target Device) parameters determine whether or not a
user has user access to target devices connected to an appliance. The user
does not have access to the appliance, unless granted by Query Mode
(Appliance).
•
The Group Container, Group Container Mask, and Target Mask fields are
only used for group query modes and are required when performing an
appliance or device query.
•
The Group Container field specifies the organizational unit (ou) created in
Active Directory by the administrator as the location for group objects.
590-1058-640A
5.1 Configuring LDAP in the user interface
69