Fortinet Technologies Inc. Page 128 FortiVoice Enterprise Phone System 4.0.0 Administration Guide
Figure 38: Advanced Options section
Testing LDAP profile queries
After you have created an LDAP profile, you should test each enabled query in the LDAP profile
to verify that the FortiVoice unit can connect to the LDAP server, that the LDAP directory
contains the required attributes and values, and that the query configuration is correct.
When testing a query in an LDAP profile, you may encounter error messages that indicate failure
of the query and how to fix the problem.
To verify user authentication options
1. Go to Phone System > Profiles > LDAP.
GUI field Description
Timeout (seconds) Enter the maximum amount of time in seconds that the FortiVoice
unit will wait for query responses from the LDAP server.
Protocol version
Select the LDAP protocol version used by the LDAP server.
Enable cache Enable to cache LDAP query results.
Caching LDAP queries can introduce a delay between when you
update LDAP directory information and when the FortiVoice unit
begins using that new information, but also has the benefit of
reducing the amount of LDAP network traffic associated with
frequent queries for information that does not change frequently.
If this option is enabled but queries are not being cached, inspect
the value of TTL. Entering a TTL value of 0 effectively disables
caching.
TTL (minutes) Enter the amount of time, in minutes, that the FortiVoice unit will
cache query results. After the TTL has elapsed, cached results
expire, and any subsequent request for that information causes the
FortiVoice unit to query the LDAP server, refreshing the cache.
The default TTL value is 1440 minutes (one day). The maximum
value is 10080 minutes (one week). Entering a value of 0 effectively
disables caching.
This option is applicable only if Enable cache is enabled.
Enable user
password change
Enable if you want to allow FortiVoice web portal users to change
their password.
Password schema Select your LDAP server’s user schema style, either OpenLDAP or
Active Directory.