Dell PowerEdge MX7000 EMC OpenManage Enterprise-Modular Edition Version 1.20.0 - Page 50

Deleting directory services, Configuring login security settings, Configuring login IP range

Page 50 highlights

a. If you have selected the directory type as AD, enter the following details: ● Server Port number-The server port number can be between 1 and 65535 ● Network Timeout and Search Timeout in seconds ● Select the Certificate Validation checkbox ● Click Select a file to browse and upload a certificate b. If you have selected the directory type as LDAP, enter the following details: ● Server Port number-The server port number can be between 1 and 65535 ● Base Distinguished Name to Search ● Attribute of User Login, Attribute of Group Membership, and Search Filter ● Network Timeout and Search Timeout in seconds ● Select the Certificate Validation checkbox ● Click Select a file to browse and upload a certificate NOTE: If the Certificate Validation check box is selected, enter the FQDN of the domain controller in the Method field. The certificate validation is successful only if the details of the Issuing Authority in the certificate and the FQDN match. Deleting directory services To delete directory services: 1. From the main menu, click Application Settings > Users > Directory Services. 2. Select the directory service that you want to delete and click Delete. Configuring login security settings OME-Modular supports IP range-based access restriction. You can restrict access to only a specified range of IP addresses. You can also configure lockout policies that enforce delays after certain number of failed login attempts. Configuring login IP range 1. Click Application Settings > Security > Login IP Range. 2. Select Enable IP Range. 3. Enter the IP range in the CIDR format. For IPv4, enter the IP address in the format-192.168.100.14/24. For IPv6, enter the IP address in the format- 2001:db8::/24. Configuring login lockout policy 1. Click Application Settings > Security > Login Lockout Policy. 2. Select By User Name to enable user account-based lockout. Select By IP Address to enable IP address-based lockout. 3. Enter the lockout details: a. Lockout Fail Count: The number of failed login attempts. Valid values are between 2 and 16. b. Lockout Fail Window: The time within which subsequent failed logins are registered. Valid time is between 2 seconds and 65,535 seconds. c. Lockout Penalty Time: Time for which the logins are restricted. Valid time is between 2 seconds and 65,535 seconds. If the IP is still unavailable, ensure that: ● The network cable is connected. ● If DHCP is configured, ensure that the cable is connected to a ToR switch that has connectivity to the DHCP server. 50 Logging in to OME-Modular

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122

a.
If you have selected the directory type as AD, enter the following details:
Server Port
number—The server port number can be between 1 and 65535
Network Timeout
and
Search Timeout
in seconds
Select the
Certificate Validation
checkbox
Click
Select a file
to browse and upload a certificate
b.
If you have selected the directory type as LDAP, enter the following details:
Server Port
number—The server port number can be between 1 and 65535
Base Distinguished Name to Search
Attribute of User Login
,
Attribute of Group Membership
, and
Search Filter
Network Timeout
and
Search Timeout
in seconds
Select the
Certificate Validation
checkbox
Click
Select a file
to browse and upload a certificate
NOTE:
If the
Certificate Validation
check box is selected, enter the FQDN of the domain controller in the
Method
field. The certificate validation is successful only if the details of the Issuing Authority in the certificate and the
FQDN match.
Deleting directory services
To delete directory services:
1.
From the main menu, click
Application Settings
>
Users
>
Directory Services
.
2.
Select the directory service that you want to delete and click
Delete
.
Configuring login security settings
OME–Modular supports IP range-based access restriction. You can restrict access to only a specified range of IP addresses.
You can also configure lockout policies that enforce delays after certain number of failed login attempts.
Configuring login IP range
1.
Click
Application Settings
>
Security
>
Login IP Range
.
2.
Select
Enable IP Range
.
3.
Enter the IP range in the CIDR format.
For IPv4, enter the IP address in the format—192.168.100.14/24. For IPv6, enter the IP address in the format—
2001:db8::/24.
Configuring login lockout policy
1.
Click
Application Settings
>
Security
>
Login Lockout Policy
.
2.
Select
By User Name
to enable user account-based lockout. Select
By IP Address
to enable IP address-based lockout.
3.
Enter the lockout details:
a.
Lockout Fail Count: The number of failed login attempts. Valid values are between 2 and 16.
b.
Lockout Fail Window: The time within which subsequent failed logins are registered. Valid time is between 2 seconds and
65,535 seconds.
c.
Lockout Penalty Time: Time for which the logins are restricted. Valid time is between 2 seconds and 65,535 seconds.
If the IP is still unavailable, ensure that:
The network cable is connected.
If DHCP is configured, ensure that the cable is connected to a ToR switch that has connectivity to the DHCP server.
50
Logging in to OME-Modular