ProSecure Unified Threat Management (UTM) Appliance

Table 99. Add Domain screen settings (continued)

Setting

Description

 

 

 

 

UID Attribute

LDAP only

The attribute in the LDAP directory that contains the user’s

 

 

identifier (UID).

 

 

For an Active Directory, enter sAMAccountName.

 

 

For an OpenLDAP directory, enter uid.

 

 

 

Member Groups

 

This field is optional. The attribute that is used to identify the

Attribute

 

groups that an entry belongs to.

 

 

For an Active Directory, enter memberOf.

 

 

For OpenLDAP, you can enter a customized attribute to

 

 

identify the groups of an entry.

 

 

 

Group Members

 

This field is optional. The attribute that is used to identify the

Attribute

 

members of a group.

 

 

For an Active Directory, enter member.

 

 

For OpenLDAP, you can enter a customized attribute to

 

 

identify the members of a group.

Additional Filter

LDAP and Active

This field is optional. A filter that is used when the UTM is

 

Directory

searching the LDAP server for matching entries while

 

 

excluding others. (Use the format described by RFC 2254.)

 

 

The following search term examples match users only:

 

 

Active Directory. objectClass=user

 

 

Open LDAP. objectClass=posixAccount

 

 

 

Radius Port

All RADIUS

The port number for the RADIUS server. You can enter a value

 

authentication

between 1 and 65535. The default port number is 1812.

 

types except

 

Repeat

The period in seconds that the UTM waits for a response from

MSCHAP and

 

MSCHAPv2

a RADIUS server. You can enter a value between 1 and 10.

 

 

The default is 3 seconds.

Timeout

 

The maximum number of times that the UTM attempts to

 

 

connect to a RADIUS server. You can enter a value between 3

 

 

and 30. The default is 5 times.

 

 

 

4.Click Apply to save your settings. The domain is added to the List of Domains table.

5.If you use local authentication, make sure that it is not disabled: in the Local Authentication section of the Domain screen (see Figure 232 on page 388), select the No radio button.

Note: A combination of local and external authentication is supported.

WARNING:

If you disable local authentication, make sure that there is at least one external administrative user; otherwise, access to the UTM is blocked.

6.If you change local authentication, click Apply in the Domain screen to save your settings.

Manage Users, Authentication, and VPN Certificates

393

Page 393
Image 393
NETGEAR STM150EW-100NAS, UTM5EW-100NAS manual 393