User`s guide

Table Of Contents
5-39
Basic Configuration
The LDAP Parameters Menu allows you to define the following parameters:
Enable: Enables/disables LDAP authentication. (Default = Off.)
PrimaryHost: Defines the IP address or domain name (up to 64 characters) for
the primary LDAP server. (Default = undefined.)
SecondaryHost: Defines the IP address or domain name (up to 64 characters) for
the secondary (fallback) LDAP server. (Default = undefined.)
LDAPPort: Defines the port that will be used to communicate with the LDAP
server. (Default = 389.)
TLS/SSL: Enables/Disables TLS/SSL encryption. Note that when TLS/SSL
encryption is enabled, the LDAP Port should be set to 636. (Default = Off.)
BindType: Sets the LDAP bind request password type. Note that in the Text
Interface, when the Bind Type is set to "Kerberos," the LDAP menu will include an
additional prompt that is used to select Kerberos parameters. In the Web Interface,
Kerberos parameters are defined using the prompts at the bottom of the menu.
(Default = Simple.)
SearchBindDN: The username that will be allowed to search the LDAP directory.
(Default = undefined.)
SearchBindPassword: The Password for the user who is allowed to search the
LDAP directory. (Default = undefined.)
UserSearchBaseDN: The directory location for user searches.
(Default = undefined.)
UserSearchFilter: Selects the attribute that lists the user name. Note that this
attribute should always end with "=%S" (no quotes.) (Default = undefined.)
GroupMembershipAttribute: Selects the attribute that list group membership(s).
(Default = undefined.)
GroupMembershipValueType: (Default = DN.)
Fallback: Enables/Disables the LDAP fallback feature. When enabled, the VMR/
NPS will revert to it's own internal user directory (see Section 5.5) if no defined
users are found via the LDAP server. In this case, port access rights will then be
granted as specified in the default LDAP group. (Default = Off.)
KerberosSetup: Kerberos is a network authentication protocol, which provides
a secure means of identity verification for users who are communicating via a
non-secure network. In the Text Interface, Kerberos parameters are selected via a
submenu that is only available when Kerberos is selected as Bind Type. In the Web
Browser Interface, Kerberos parameters are defined via the main LDAP Parameters
menu. The following parameters are available:.
Port: (Default = 88.)
Realm: (Default = Undefined.)
KeyDistributionCenters(KDC1throughKDC5): (Default = Undefined.)
DomainRealms1through5: (Default = Undefined.)