Chapter 31 AAA Server

Bind DN

A bind DN is used to authenticate with an LDAP/AD server. For example a bind DN of cn=zywallAdmin allows the ZyWALL to log into the LDAP/AD server using the user name of zywallAdmin. The bind DN is used in conjunction with a bind password. When a bind DN is not specified, the ZyWALL will try to log in as an anonymous user. If the bind password is incorrect, the login will fail.

31.2 Active Directory or LDAP Server Summary

Use the Active Directory or LDAP screen to manage the list of AD or LDAP servers the ZyWALL can use in authenticating users.

Click Configuration > Object > AAA Server > Active Directory (or LDAP) to display the Active Directory (or LDAP) screen.

Figure 266 Configuration > Object > AAA Server > Active Directory (or LDAP)

The following table describes the labels in this screen.

Table 153 Configuration > Object > AAA Server > Active Directory (or LDAP)

LABEL

DESCRIPTION

Add

Click this to create a new entry.

 

 

Edit

Double-click an entry or select it and click Edit to open a screen where you can modify the

 

entry’s settings.

 

 

Remove

To remove an entry, select it and click Remove. The ZyWALL confirms you want to remove

 

it before doing so.

 

 

Object

Select an entry and click Object References to open a screen that shows which settings

References

use the entry. See Section 7.3.2 on page 122 for an example.

 

 

#

This field displays the index number.

 

 

Server Address

This is the address of the AD or LDAP server.

 

 

Base DN

This specifies a directory. For example, o=ZyXEL, c=US.

31.2.1 Adding an Active Directory or LDAP Server

Click Object > AAA Server > Active Directory (or LDAP) to display the Active Directory (or LDAP) screen. Click the Add icon or an Edit icon to display the following screen. Use this screen to create a new AD or LDAP entry or edit an existing one.

 

403

ZyWALL 110/310/1100 Series User’s Guide