27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 3 LDAP Queries<br />

Understanding How LDAP Works with AsyncOS<br />

Figure 3-1 LDAP Configuration<br />

OL-25137-01<br />

When you work with LDAP directories, the Cisco <strong>IronPort</strong> appliance can be used in conjunction with an<br />

LDAP directory server to accept recipients, route messages, and/or masquerade headers. LDAP group<br />

queries can also be used in conjunction with message filters to create rules for handling messages as they<br />

are received by the Cisco <strong>IronPort</strong> appliance.<br />

Figure 3-1 demonstrates how the Cisco <strong>IronPort</strong> appliance works with LDAP:<br />

Sending MTA<br />

SMTP<br />

1 HELO<br />

Firewall<br />

Step 1 The sending MTA sends a message to the public listener “A” via SMTP.<br />

Step 2 The Cisco <strong>IronPort</strong> appliance queries the LDAP server defined via the System Administration > LDAP<br />

page (or by the global ldapconfig command).<br />

Step 3 Data is received from the LDAP directory, and, depending on the queries defined on the System<br />

Administration > LDAP page (or in the ldapconfig command) that are used by the listener:<br />

– the message is routed to the new recipient address, or dropped or bounced<br />

– the message is routed to the appropriate mailhost for the new recipient<br />

– From:, To:, and CC: message headers are re-written based upon the query<br />

<strong>IronPort</strong> appliance<br />

with LDAP enabled<br />

Recipient email address (local)<br />

Mailhost information<br />

Mail routing information<br />

Group information<br />

SMTP AUTH<br />

– further actions as defined by rcpt-to-group or mail-from-group message filter rules (used in<br />

conjunction with configured group queries).<br />

Note You can configure your Cisco <strong>IronPort</strong> appliance to connect to multiple LDAP servers. When you do<br />

this, you can configure the LDAP profile settings for load-balancing or failover. For more information<br />

about working with multiple LDAP servers, see Configuring AsyncOS To Work With Multiple LDAP<br />

Servers, page 3-46.<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

A<br />

2<br />

DC=example,DC=com<br />

3<br />

3-3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!