ZyXEL ENC User Guide - Page 289

Table 153, LABEL, DESCRIPTION, Application, ENC User's Guide, Note: This is only for LDAP.

Page 289 highlights

Chapter 8 Application The following table describes the labels in this screen. Table 153 AAA Server: Add - AD Server/LDAP Server LABEL DESCRIPTION Profile Name Enter a descriptive name (up to 30 alphanumerical characters) for identification purposes. Description Enter the description of each server, if any. You can use up to 60 printable ASCII characters. Server Address Enter the address of the AD server. Backup Server Address If the AD has a backup server, enter its address here. Port Specify the port number on the AD to which the NXC5200 sends authentication requests. Enter a number between 1 and 65535. Base DN This port number should be the same on all AD or LDAP server(s) in this group. Specify the directory (up to 127 alphanumerical characters). For example, o=ZyXEL, c=US. Use SSL Select Use SSL to establish a secure connection to the AD or LDAP server(s). Search time limit Specify the timeout period (between 1 and 300 seconds) before the NXC5200 disconnects from the AD server. In this case, user authentication fails. Search timeout occurs when either the user information is not in the AD or the AD is down. Bind DN Specify the bind DN for logging into the AD server. Enter up to 127 alphanumerical characters. For example, cn=zyAdmin specifies zyAdmin as the user name. Password If required, enter the password (up to 15 alphanumerical characters) for the NXC5200 to bind (or log in) to the AD server. Login Name Attribute Enter the type of identifier the users are to use to log in. For example "name" or "e-mail address". Alternative Login If there is a second type of identifier that the users can use to log in, enter it here. For Name Attribute example "name" or "e-mail address". Group Membership Attribute Enter the name of the attribute that the NXC5200 is to check to determine to which group a user belongs. The value for this attribute is called a group identifier; it determines to which group a user belongs. You can add ext-group-user user objects to identify groups based on these group identifier values. Enable For example you could have an attribute named "memberOf" with values like "sales", "RD", and "management". Then you could also create a ext-group-user user object for each group. One with "sales" as the group identifier, another for "RD" and a third for "management". Select this to enable domain authentication for MSChap. User Name Note: This is only for LDAP. Enter the user name for the user who has rights to add a machine to the domain. User Password Note: This is only for LDAP. Enter the password for the associated user name. Realm Note: This is only for LDAP. Enter the realm IP address. OK Cancel Note: This is only for LDAP. Click OK to save the changes. Click Cancel to discard the changes. ENC User's Guide 289

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390

Chapter 8 Application
ENC User’s Guide
289
The following table describes the labels in this screen.
Table 153
AAA Server: Add - AD Server/LDAP Server
LABEL
DESCRIPTION
Profile Name
Enter a descriptive name (up to 30 alphanumerical characters) for identification purposes.
Description
Enter the description of each server, if any. You can use up to 60 printable ASCII
characters.
Server Address
Enter the address of the AD server.
Backup Server
Address
If the AD has a backup server, enter its address here.
Port
Specify the port number on the AD to which the NXC5200 sends authentication requests.
Enter a number between 1 and 65535.
This port number should be the same on all AD or LDAP server(s) in this group.
Base DN
Specify the directory (up to 127 alphanumerical characters). For example,
o=ZyXEL,
c=US
.
Use SSL
Select
Use SSL
to establish a secure connection to the AD or LDAP server(s).
Search time limit
Specify the timeout period (between 1 and 300 seconds) before the NXC5200 disconnects
from the AD server. In this case, user authentication fails.
Search timeout occurs when either the user information is not in the AD or the AD is down.
Bind DN
Specify the bind DN for logging into the AD server. Enter up to 127 alphanumerical
characters.
For example,
cn=zyAdmin
specifies
zyAdmin
as the user name.
Password
If required, enter the password (up to 15 alphanumerical characters) for the NXC5200 to
bind (or log in) to the AD server.
Login Name
Attribute
Enter the type of identifier the users are to use to log in. For example
“name” or “e-mail
address”.
Alternative Login
Name Attribute
If there is a second type of identifier that the users can use to log in, enter it here. For
example “name” or “e-mail address”.
Group
Membership
Attribute
Enter the name of the attribute that the NXC5200 is to check to determine to which group
a user belongs. The value for this attribute is called a group identifier; it determines to
which group a user belongs. You can add
ext-group-user
user objects to identify groups
based on these group identifier values.
For example you could have an attribute named “memberOf” with values like “sales”, “RD”,
and “management”. Then you could also create a
ext-group-user
user object for each
group. One with “sales” as the group identifier, another for “RD” and a third for
“management”.
Enable
Select this to enable domain authentication for MSChap.
Note: This is only for LDAP.
User Name
Enter the user name for the user who has rights to add a machine to the domain.
Note: This is only for LDAP.
User Password
Enter the password for the associated user name.
Note: This is only for LDAP.
Realm
Enter the realm IP address.
Note: This is only for LDAP.
OK
Click
OK
to save the changes.
Cancel
Click
Cancel
to discard the changes.