Cisco Systems 4.2 Server User Manual


 
6-15
Configuration Guide for Cisco Secure ACS 4.2
OL-14390-02
Chapter 6 Agentless Host Support Configuration Scenario
Basic Configuration Steps for Agentless Host Support
UserObjectClass—The value of the LDAP objectType attribute that identifies the record as a user.
Often, user records have several values for the
objectType attribute, some of which are unique to
the user, some of which are shared with other object types. In the LDAP schema shown in
Example 6-1, the user object class is specified as ieee802Device.
GroupObjectType—The name of the attribute in the group record that contains the group name. In
tIn the LDAP schema shown in
Example 6-1, this is cn.
GroupObjectClass—For MAB configuration, specify the name of a device record” that you have
set up in your LDAP schema. For example, in
Example 6-1, the group object class is
ieee802Device.
GroupAttributeName—For MAB configuration, specify the name of the LDAP attribute that
specifies a LDAP user group. For example, in
Example 6-1, each member of a LDAP user group is
specified in a uniqueMember attribute.
Server Timeout—The number of seconds that ACS waits for a response from an LDAP server
before determining that the connection with that server failed.
On Timeout Use Secondary—Determines whether ACS performs failover of LDAP
authentication attempts.
Failback Retry Delay—The number of minutes after the primary LDAP server fails to
authenticate a user that ACS resumes sending authentication requests to the primary LDAP
server first. A value of zero (0) causes ACS to always use the primary LDAP server first.
Max. Admin Connections—The maximum number of concurrent connections (greater than
zero (0)) with LDAP administrator account permissions that can run for a specific LDAP
configuration. These connections are used to search the directory for users and groups under the
User Directory Subtree and Group Directory Subtree.
Specify LDAP server configuration information:
Figure 6-7 shows the Primary LDAP Server and Secondary LDAP Server configuration sections.