Cisco Cisco Email Security Appliance C170 사용자 가이드

다운로드
페이지 1138
 
23-6
Cisco AsyncOS 8.5 for Email User Guide
 
Chapter 23      LDAP Queries
  Overview of LDAP Queries
Note
To allow the appliance to run LDAP queries when you receive or send messages, you must 
enable the LDAP query on the appropriate listener. For more information, see 
Step 14
Test a query by clicking the Test Query button. 
Enter the test parameters and click Run Test. The results of the test appear in the Connection Status 
field. If you make any changes to the query definition or attributes, click Update. For more 
information, see 
.
Note
If you have configured the LDAP server to allow binds with empty passwords, the query can pass 
the test with an empty password field.
Step 15
Submit and commit your changes.
Note
Although the number of server configurations is unlimited, you can configure only one recipient 
acceptance, one routing, one masquerading, and one group query per server.
Testing LDAP Servers
Use the Test Server(s) button on the Add/Edit LDAP Server Profile page (or the 
test
 subcommand of 
the 
ldapconfig
 command in the CLI) to test the connection to the LDAP server. AsyncOS displays a 
message stating whether the connection to the server port succeeded or failed. If you configured multiple 
LDAP servers, AsyncOS tests each server and displays individual results.
Enabling LDAP Queries to Run on a Particular Listener
To allow the appliance to run LDAP queries when you receive or send messages, you must enable the 
LDAP query on the appropriate listener.
Configuring Global Settings for LDAP Queries
The LDAP global settings define how the appliance handles all LDAP traffic.
Procedure 
Step 1
On the System Administration > LDAP page, click Edit Settings.
Step 2
Select the IP interface to use for LDAP traffic. The appliance automatically chooses an interface by 
default.
Step 3
Select the TLS certificate to use for the LDAP interface (TLS certificates added via the Network > 
Certificates page or the 
certconfig
 command in the CLI are available in the list, see