Manage Users, Authentication, and VPN Certificates
299
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
4. Click Apply to save your settings. The domain is added to the List of Domains table.
5. If you use local authentication, make sure that it is not disabled: in the Local Authentication
section of the Domain screen (see Figure 197 on page 296), select the No radio button.
Note: A combination of local and external authentication is supported.
WARNING:
If you disable local authentication, make sure that there is at least
one external administrative user; otherwise, access to the VPN
firewall is blocked.
6. If you do change local authentication, click Apply in the Domain screen to save your
settings.
To delete one or more domains:
1. In the List of Domains table, select the check box to the left of each domain that you
want to delete, or click the Select All table button to select all domains.
2. Click the Delete table button.
Note: You cannot delete the geardomain default domain.
LDAP Base DN The LDAP distinguished name (DN) that is required to access the LDAP
authentication server. This should be a user in the LDAP directory who has read
access to all the users that you would like to import into the VPN firewall. The Bind
DN field accepts two formats:
A display name in the DN format. For example:
cn=Jamie Hanson,cn=users,dc=test,dc=com.
A Windows login account name in email format. For example:
jhanson@testAD.com. This last type of bind DN can be used only for a Windows
LDAP server.
Active Directory
Domain The Active Directory domain name that is required for Microsoft Active Directory
authentication.
Table 75. Add Domain screen settings (continued)
Setting Description