Cisco Cisco Email Security Appliance C160 Mode D'Emploi

Page de 1211
 
25-16
AsyncOS 9.1.2 for Cisco Email Security Appliances User Guide
 
Chapter 25      LDAP Queries
  Working with LDAP Queries
Click to select the Allow check box for the Permission permission.
Step 3
Configure the Cisco Messaging Gateway
Use 
ldapconfig
 on the Command Line Interface (CLI) to create an LDAP server entry with the 
following information.
Hostname of an Active Directory or Exchange server
Port 3268
Base DN matching the root naming context of the domain
Authentication type Anonymous
Anonymous Bind Setup for Active Directory
The following setup instructions allow you to make specific data available to anonymous bind queries 
of Active Directory and Exchange 2000 servers in the Microsoft Windows Active Directory. Anonymous 
bind of an Active Directory server will send the username 
anonymous
 with a blank password.
Note
If a password is sent to an Active Directory server while attempting anonymous bind, authentication may 
fail.
Procedure 
Step 1
Determine required Active Directory permissions.
Using the ADSI Edit snap-in or the LDP utility, you must modify the permissions to the attributes 
of the following Active Directory objects.
The root of the domain naming context for the domain against which you want to make queries.
All OU and CN objects that contain users against which you wish to query email information.
The following table shows the required permissions to be applied to all of the needed containers.
Step 2
Set Active Directory Permissions
Open ADSIEdit form the Windows 2000 Support Tools.
Locate the Domain Naming Context folder. This folder has the LDAP path of your domain.
Right click the Domain Naming Context folder, and then click Properties.
Click Security.
Click Advanced.
Click Add.
User Object
Permissions
Inheritance
Permission 
Type
ANONYMOUS LOGON
List Contents
Container Objects
Object
ANONYMOUS LOGON
List Contents
Organizational Unit 
Objects
Object
ANONYMOUS LOGON
Read Public Information
User Objects
Property
ANONYMOUS LOGON
Read Phone and Mail Options
User Objects
Property