Unified Security Gateway User's Guide

Chapter 38 AAA Server
ZyWALL USG 300 User’s Guide
534
Figure 391 Object > AAA Server > Active Directory (or LDAP) > Default
The following table describes the labels in this screen.
38.3 Active Directory or LDAP Group Summary
You can configure a group of AD or LDAP servers in the Active Directory (or LDAP) >
Group screen. This is useful if you have more than one AD server or more than one LDAP
server for user authentication in a network. You can create up to 16 AD server groups with up
to four members in each group on the ZyWALL. You can also create up to 16 LDAP server
groups with up to four members in each group on the ZyWALL.
Table 176 Object > AAA Server > Active Directory (or LDAP) > Default
LABEL DESCRIPTION
Host Enter the IP address (in dotted decimal notation) or the fully-qualified domain
name (up to 63 alphanumerical characters) of an AD or LDAP server.
Port Specify the port number on the AD or LDAP server to which the ZyWALL sends
authentication requests. Enter a number between 1 and 65535. The default is 389.
Bind DN Specify the bind DN for logging into the LDAP server. Enter up to 63
alphanumerical characters.
For example,
cn=zywallAdmin specifies zywallAdmin as the user name.
Password If required, enter the password (up to 15 alphanumerical characters) for the
ZyWALL to bind (or log in) to the AD or LDAP server.
Base DN Specify the directory (up to 63 alphanumerical characters). For example,
o=ZyXEL, c=US.
CN Identifier Specify the unique common name that uniquely identifies a record in the AD or
LDAP directory. Enter up to 63 alphanumerical characters.
Search time limit Specify the timeout period (between 1 and 300 seconds) before the ZyWALL
disconnects from the AD or LDAP server. In this case, user authentication fails.
The search timeout occurs when either the user information is not in the LDAP
server or the server is down.
Use SSL Select Use SSL to establish a secure connection to the AD or LDAP server.
Apply Click Apply to save the changes.
Reset Click Reset to start configuring this screen again.