User Guide
25-12
AsyncOS 9.1.2 for Cisco Email Security Appliances User Guide
Chapter 25 LDAP Queries
Working with LDAP Queries
Working with LDAP Queries
You create an entry in the LDAP server profile for each type of LDAP query you want to perform. When
you create LDAP queries, you must enter the query syntax for your LDAP server. Please note that the
queries you construct should be tailored and specific to your particular implementation of LDAP
directory services, particularly if you have extended your directory with new object classes and attributes
to accommodate the unique needs of your directory.
Related Topics
• Types of LDAP Queries, page 25-12
• Base Distinguishing Name (DN), page 25-13
• LDAP Query Syntax, page 25-13
• Secure LDAP (SSL), page 25-14
• Routing Queries, page 25-14
• Allowing Clients to Bind to the LDAP Server Anonymously, page 25-14
• Testing LDAP Queries, page 25-17
• Troubleshooting Connections to LDAP Servers, page 25-18
Types of LDAP Queries
• Acceptance queries. For more information, see Using Acceptance Queries For Recipient
Validation, page 25-19.
• Routing queries. For more information, see Using Routing Queries to Send Mail to Multiple Target
Addresses, page 25-20.
• Certificate Authentication queries. For more information, see Checking the Validity of a Client
Certificate, page 26-51.
• Masquerading queries. For more information, see Using Masquerading Queries to Rewrite the
Envelope Sender, page 25-21.
• Group queries. For more information, see Using Group LDAP Queries to Determine if a Recipient
is a Group Member, page 25-23.
• Domain-based queries. For more information, see Using Domain-based Queries to Route to a
Particular Domain, page 25-26.
• Chain queries. For more information, see Using Chain Queries to Perform a Series of LDAP
Queries, page 25-28.
You can also configure queries for the following purposes:
• Directory harvest prevention. For more information, see Understanding LDAP Queries,
page 25-2.
- BASE - Configure the query base.
- COMPATIBILITY - Set LDAP protocol compatibility options.
[]>