Cisco Cisco Email Security Appliance C160 Mode D'Emploi
26-15
User Guide for AsyncOS 9.8 for Cisco Email Security Appliances
Chapter 26 LDAP Queries
Working with LDAP Queries
–
All OU and CN objects that contain users against which you wish to query email information.
The following table shows the required permissions to be applied to all of the needed containers.
Step 2
Set Active Directory Permissions
–
Open ADSIEdit form the Windows 2000 Support Tools.
–
Locate the Domain Naming Context folder. This folder has the LDAP path of your domain.
–
Right click the Domain Naming Context folder, and then click Properties.
–
Click Security.
–
Click Advanced.
–
Click Add.
–
Click the User Object Everyone, and then click OK.
–
Click the Permission Type tab.
–
Click Inheritance from the Apply onto box.
–
Click to select the Allow check box for the Permission permission.
Step 3
Configure the Cisco Messaging Gateway
Use
ldapconfig
on the Command Line Interface (CLI) to create an LDAP server entry with the
following information.
–
Hostname of an Active Directory or Exchange server
–
Port 3268
–
Base DN matching the root naming context of the domain
–
Authentication type Anonymous
Anonymous Bind Setup for Active Directory
The following setup instructions allow you to make specific data available to anonymous bind queries
of Active Directory and Exchange 2000 servers in the Microsoft Windows Active Directory. Anonymous
bind of an Active Directory server will send the username
of Active Directory and Exchange 2000 servers in the Microsoft Windows Active Directory. Anonymous
bind of an Active Directory server will send the username
anonymous
with a blank password.
Note
If a password is sent to an Active Directory server while attempting anonymous bind, authentication may
fail.
fail.
Procedure
Step 1
Determine required Active Directory permissions.
User Object
Permissions
Inheritance
Permission Type
Everyone
List Contents
Container Objects
Object
Everyone
List Contents
Organizational Unit Objects
Object
Everyone
Read Public Information
User Objects
Property
Everyone
Read Phone and Mail
Options
Options
User Objects
Property