Chapter 28 AAA Server

 

 

 

 

Table 110 aaa group server ad Commands (continued)

 

COMMAND

DESCRIPTION

 

[no] server domain-auth

Activates server domain authentication. The no

 

activate

parameter deactivates it.

 

server domain-auth domain-

Adds the NetBIOS name of the AD server. The NXC

 

name <netbios_name>

uses it with the user name in the format

 

 

NetBIOS\USERNAME to do authentication.

 

 

The NXC uses the format USERNAME@realm if you

 

 

do not configure the NetBIOS name.

 

 

 

 

server domain-auth username

Sets the user name and password for domain

 

[username] password

authentication.

 

[password]

 

 

server domain-auth realm

Sets the realm for domain authentication.

 

[realm]

 

 

[no] server port port_no

Sets the AD port number. Enter a number between 1

 

 

and 65535. The default is 389. The no command

 

 

clears this setting.

 

[no] server search-time-limit

Sets the search timeout period (in seconds). Enter a

 

time

number between 1 and 300. The no command clears

 

 

this setting and set this to the default setting of 5

 

 

seconds.

 

 

 

 

[no] server ssl

Enables the NXC to establish a secure connection to

 

 

the AD server. The no command disables this feature.

28.2.2 aaa group server ldap Commands

The following table lists the aaa group server ldap commands you use to configure a group of LDAP servers.

Table 111 aaa group server ldap Commands

COMMAND

DESCRIPTION

clear aaa group server ldap

Deletes all LDAP server groups or the specified LDAP

[group-name]

server group.

 

Note: You can NOT delete a server group

 

that is currently in use.

 

 

show aaa group server ldap group-

Displays the specified LDAP server group settings.

name

 

[no] aaa group server ldap group-

Sets a descriptive name for an LDAP server group.

name

Use this command to enter the sub-command mode.

 

The no command deletes the specified server group.

aaa group server ldap rename

Changes the descriptive name for an LDAP server

group-name group-name

group.

 

 

aaa group server ldap group-name

Enter the sub-command mode.

[no] server alternative-cn-

Sets the second type of identifier that the users can

identifier uid

use to log in if any. For example “name” or “e-mail

 

address”. The no command clears this setting.

[no] server basedn basedn

Sets a base distinguished name (DN) to point to the

 

LDAP directory on the LDAP server group. The no

 

command clears this setting.

 

189

NXC CLI Reference Guide