ZyXEL Communications 100 Series Network Router User Manual


 
Chapter 39 AAA Server
ZyWALL USG 100/200 Series User’s Guide
630
Figure 466 Object > AAA Server > Active Directory (or LDAP) > Group > Add
The following table describes the labels in this screen.
Table 213 Object > AAA Server > Active Directory (or LDAP) > Group > Add
LABEL DESCRIPTION
Configuration All AD or LDAP servers in a group share the same settings in the fields below.
Name Enter a descriptive name (up to 63 alphanumerical characters). for identification
purposes.
Port Specify the port number on the LDAP server(s) to which the ZyWALL sends
authentication requests. Enter a number between 1 and 65535.
This port number should be the same on all AD or LDAP server(s) in this group.
Password If required, enter the password (up to 15 alphanumerical characters) the ZyWALL
uses to log into the AD or LDAP server(s).
Base DN Specify the top level directory in the directory. For example,
o=ZyXEL, c=US.
binddn Specify the bind DN for logging into the AD or LDAP server(s). For example,
cn=zywallAdmin specifies zywallAdmin as the user name.
CN Identifier Specify the unique common name that uniquely identifies a record in the AD or
LDAP directory. Enter up to 63 alphanumerical characters.
Search time
limit
Specify the timeout period (between 1 and 300 seconds) before the ZyWALL
disconnects from the AD or LDAP server. In this case, user authentication fails.
Search timeout occurs when either the user information is not in the AD or LDAP
server(s) or the AD or LDAP server(s) is down.
Use SSL Select Use SSL to establish a secure connection to the AD or LDAP server(s).
Host Members The ordering of the LDAP servers is important as the ZyWALL uses the AD or
LDAP servers for user authentication in the order they appear in this table.
# This field displays the index number.
Members Specify the URI (Uniform Resource Identifier) of an AD or LDAP server. You can
enter the IP address (in dotted decimal notation) or the fully qualified domain
name (FQDN; up to 63 alphanumerical characters) of the AD or LDAP server.