User Guide

25-7
AsyncOS 9.1.2 for Cisco Email Security Appliances User Guide
Chapter 25 LDAP Queries
Overview of LDAP Queries
Enabling LDAP Queries to Run on a Particular Listener
To allow the appliance to run LDAP queries when you receive or send messages, you must enable the
LDAP query on the appropriate listener.
Related Topics
Configuring Global Settings for LDAP Queries, page 25-7
Example of Creating an LDAP Server Profile, page 25-7
Enabling LDAP Queries on a Public Listener, page 25-8
Enabling LDAP Queries on a Private Listener, page 25-9
Configuring Global Settings for LDAP Queries
The LDAP global settings define how the appliance handles all LDAP traffic.
Procedure
Step 1 On the System Administration > LDAP page, click Edit Settings.
Step 2 Select the IP interface to use for LDAP traffic. The appliance automatically chooses an interface by
default.
Step 3 Select the TLS certificate to use for the LDAP interface (TLS certificates added via the Network >
Certificates page or the
certconfig command in the CLI are available in the list, see Overview of
Encrypting Communication with Other MTAs, page 23-1).
Step 4 Submit and commit your changes.
Example of Creating an LDAP Server Profile
In the following example, the System Administration > LDAP page is used to define an LDAP server for
the appliance to bind to, and queries for recipient acceptance, routing, and masquerading are configured.
Note There is a 60 second connection attempt time-out for LDAP connections (which covers the DNS lookup,
the connection itself, and, if applicable, the authentication bind for the appliance itself). After the first
failure, AsyncOS immediately starts trying other hosts in the same server (if you specified more than
one in the comma separated list). If you only have one host in the server, AsyncOS continues attempting
to connect to it.