06.05.2013 Views

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

User Guide for Cisco Secure Access Control Server - Stewing Home

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Generic LDAP<br />

12-32<br />

Step 4 If you are creating a configuration:<br />

a. Click Create New Configuration.<br />

b. Type a name <strong>for</strong> the new configuration <strong>for</strong> generic LDAP in the box provided.<br />

c. Click Submit.<br />

ACS lists the new configuration in the External <strong>User</strong> Database Configuration table.<br />

<strong>User</strong> <strong>Guide</strong> <strong>for</strong> <strong>Cisco</strong> <strong>Secure</strong> <strong>Access</strong> <strong>Control</strong> <strong>Server</strong> 4.2<br />

Chapter 12 <strong>User</strong> Databases<br />

Step 5 Under External <strong>User</strong> Database Configuration, select the name of the LDAP database that to configure.<br />

Note If only one LDAP configuration exists, the name of that configuration appears instead of the list.<br />

Proceed to Step 6.<br />

Step 6 Click Configure.<br />

Caution If you click Delete, the configuration of the selected LDAP database is deleted.<br />

Step 7 If you do not want ACS to filter LDAP authentication requests by username, under Domain Filtering,<br />

select Process all usernames.<br />

Step 8 If you want to limit authentications processed by this LDAP configuration to usernames with a specific<br />

domain qualification:<br />

Note For in<strong>for</strong>mation about domain filtering, see Domain Filtering, page 12-24.<br />

a. Under Domain Filtering, select Only process usernames that are domain qualified.<br />

b. From the Qualified by list, select the applicable type of domain qualification, either Suffix or Prefix.<br />

Only one type of domain qualification is supported per LDAP configuration.<br />

For example, if you want this LDAP configuration to authenticate usernames that begin with a<br />

specific domain name, select Prefix. If you want this LDAP configuration to authenticate usernames<br />

that end with a specific domain name, select Suffix.<br />

c. In the Domain Qualifier box, type the name of the domain <strong>for</strong> which you this LDAP configuration<br />

should authenticate usernames. Include the delimiting character that separates the user ID from the<br />

domain name. Ensure that the delimiting character appears in the applicable position: at the end of<br />

the domain name if Prefix is selected on the Qualified by list; at the beginning of the domain name<br />

if Suffix is selected on the Qualified by list.<br />

Only one domain name is supported per LDAP configuration. You can type up to 512 characters.<br />

d. If you want ACS to remove the domain qualifier be<strong>for</strong>e submitting it to the LDAP database, check<br />

the Strip domain be<strong>for</strong>e submitting username to LDAP server check box.<br />

e. If you want ACS to pass the username to the LDAP database without removing the domain qualifier,<br />

clear the Strip domain be<strong>for</strong>e submitting username to LDAP server check box.<br />

Step 9 If you want to enable ACS to strip domain qualifiers from usernames be<strong>for</strong>e submitting them to an LDAP<br />

server:<br />

OL-14386-02

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!