Tripp Lite B093-004-2E4U-V 4-Port Console Server with 4G LTE Cellular Gateway, Dual GbE NIC, 4Gb Flash and Dual SIM

Owner's Manual - Page 174

For B093-004-2E4U-V. Also, The document are for others Tripp Lite models: B093-00X-2E4U-X, B097-016/048, B098-016/048, B098-016-V

PDF File Manual, 285 pages, Read Online | Download pdf file

B093-004-2E4U-V photo
Loading ...
Loading ...
Loading ...
174
9. Authentication
9.1.8 Remote Groups with LDAP Authentication
Unlike RADIUS, LDAP has built-in support for group provisioning, which makes setting up remote groups easier. The console
server will retrieve a list of all the remote groups the user is a direct member of and compare their names with local groups on
the console server.
Note: Any spaces in the group name will be converted to underscores.
For example, in an existing Active Directory setup, a group of users may be part of the UPS Admin and Router Admin
groups. On the console server, these users will be required to have access to a group Router_Admin, with access to port 1
(connected to the router), and another group UPS_Admin, with access to port 2 (connected to the UPS). Once LDAP is set
up, users that are members of each group will have the appropriate permissions to access the router and UPS.
Currently, the only LDAP directory service that supports group provisioning is Microsoft Active Directory. Support is planned for
OpenLDAP later.
To enable group information to be used with an LDAP server:
• Complete the fields for standard LDAP authentication, including LDAP Server Address, Server Password, LDAP Base DN,
LDAP Bind DN and LDAP Username Attribute.
• Enter memberOf for LDAP Group Membership Attribute, as group membership is currently only supported on Active
Directory servers.
• If required, enter the group information for LDAP Console Server Group DN and/or LDAP Administration Group DN.
A user must be a member of the LDAP Console Server Group DN group in order to gain access to the console and user
interface. For example, the user must be a member of “MyGroup” on the Active Server to gain access to the console server.
Additionally, a user must be a member of the LDAP Administration Group DN in order to gain administrator access to the
console server. For example, the user must be a member of “AdminGroup” on the Active Server to receive administration
privileges on the console server.
• Click Apply.
• Ensure the LDAP service is operational and group names are correct within the Active Directory.
Loading ...
Loading ...
Loading ...