CHAPTER16 Services
Mediant 4000 SBC | User's Manual
■ Management: To use an LDAP server for management where it does user login authentication
and user authorization, you need to configure the LDAP Server Group as a Management type.
Additional LDAP-based management parameters need to be configured, as described in
Enabling LDAP-based Web/CLI User Login Authentication and Authorization and Configuring
LDAP Servers.
■ Management Service: To use two different LDAP server accounts for management where
one LDAP account does user authentication and the other LDAP account does user
authorization, you need to configure two LDAP Server Groups. Configure the LDAP Server
Group for user authentication as a Management type and the LDAP Server Group for user
authorization as a Management Service type. In this setup, configure all the user-
authorization settings (i.e., Management LDAP Groups and LDAP Server Search Base DN)
only for the Management Service-type LDAP Server Group (instead of for the Management-
type LDAP Server Group).
The following procedure describes how to configure an LDAP Server Group through the Web
interface. You can also configure it through ini file [LDAPServerGroups] or CLI (configure
system > ldap ldap-server-groups).
The device provides a preconfigured LDAP Server Group
("DefaultCTRLServersGroupin") in the LDAP Server Groups table, which can be
modified or deleted.
➢ To configure an LDAP Server Group:
1. Open the LDAP Server Groups table (Setup menu > IP Network tab > RADIUS & LDAP
folder > LDAP Server Groups).
2. Click New; the following dialog box appears:
3. Configure an LDAP Server Group according to the parameters described in the table below.
4. Click Apply.
Table 16-8: LDAP Server Groups Table Parameter Descriptions
Parameter Description
General
'Index'
[LdapServerGroups_Index]
Defines an index number for the new table row.
Note: Each row must be configured with a unique index.
'Name'
name
[LdapServerGroups_Name]
Defines a descriptive name, which is used when associating
the row in other tables.
The valid value is a string of up to 20 characters.
Note:
- 218 -