14.02.2014 Views

CommandCenter Secure Gateway - Admin Guide - Version ... - Raritan

CommandCenter Secure Gateway - Admin Guide - Version ... - Raritan

CommandCenter Secure Gateway - Admin Guide - Version ... - Raritan

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 12: Remote Authentication<br />

For example, if you specify cn=Groups,dc=raritan,dc=com as the<br />

Base DN and (objectclass=group) as the Filter, then all entries that are<br />

in the Groups entry and are of type group will be returned.<br />

4. Click Next to proceed. The Trusts tab opens.<br />

AD Trust Settings<br />

In the Trusts tab, you can set up trust relationships between this new AD<br />

domain and any existing domains. A trust relationship allows resources to<br />

be accessible by authenticated users across domains. Trust relationships<br />

can be incoming, outgoing, bidirectional, or disabled. You should set up<br />

trust relationships if you want AD modules that represent different forests<br />

in AD to be able to access information from each other. The trusts you<br />

configure in CC-SG should match the trusts configured in AD.<br />

1. Click the Trusts tab. If you have configured more than one AD domain,<br />

all other domains are listed in the Trusts tab.<br />

2. For each domain in the Trust Partner column, click the Trust Direction<br />

drop-down menu, and then select the direction of trust you want to<br />

establish between the domains. Trust directions are updated in all AD<br />

modules when you make changes to one AD module.<br />

• Incoming: information will be trusted coming in from the domain.<br />

• Outgoing: information will be trusted going to the selected domain.<br />

• Bidirectional: information will be trusted in both directions from<br />

each domain.<br />

• Disabled: information will not be exchanged between the domains.<br />

3. Click Apply to save your changes, and then click OK to save the AD<br />

module and exit the window.<br />

The new AD module appears in the Security Manager screen under<br />

External AA Servers.<br />

4. Select the Authentication checkbox if you want CC-SG to use the AD<br />

module for authentication of users. Select the Authorization checkbox<br />

if you want CC-SG to use the AD module for authorization of users.<br />

5. Click Update to save your changes.<br />

Editing an AD Module<br />

Once you have configured AD modules, you can edit them at any time.<br />

To edit an AD module:<br />

1. Choose <strong>Admin</strong>istration > Security.<br />

2. Click the Authentication tab. All configured external Authorization and<br />

Authentication Servers appear in a table.<br />

140

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!