27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Working with LDAP Queries<br />

Types of LDAP Queries<br />

Base Distinguishing Name (DN)<br />

3-12<br />

- BASE - Configure the query base.<br />

- COMPATIBILITY - Set LDAP protocol compatibility options.<br />

[]><br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

Chapter 3 LDAP Queries<br />

You create an entry in the LDAP server profile for each type of LDAP query you want to perform. When<br />

you create LDAP queries, you must enter the query syntax for your LDAP server. Please note that the<br />

queries you construct should be tailored and specific to your particular implementation of LDAP<br />

directory services, particularly if you have extended your directory with new object classes and attributes<br />

to accommodate the unique needs of your directory.<br />

The following sections provide sample queries and <strong>configuration</strong> details for each type of query:<br />

Acceptance queries. For more information, see Acceptance (Recipient Validation) Queries,<br />

page 3-18.<br />

Routing queries. For more information, see Routing: Alias Expansion, page 3-20.<br />

Masquerading queries. For more information, see Masquerading, page 3-20.<br />

Group queries. For more information, see Group LDAP Queries, page 3-22.<br />

Domain-based queries. For more information, see Domain-based Queries, page 3-26.<br />

Chain queries. For more information, see Chain Queries, page 3-27.<br />

You can also configure queries for the following purposes:<br />

Directory harvest prevention. For more information, see Understanding LDAP Queries, page 3-2.<br />

SMTP authentication. For more information, see Configuring AsyncOS for SMTP Authentication,<br />

page 3-31.<br />

External authentication. For more information, Configuring External Authentication for Users,<br />

page 3-40.<br />

Spam quarantine end-user authentication query. For more information, see Spam Quarantine<br />

End-User Authentication Queries, page 3-43.<br />

Spam quarantine alias consolidation query. For more information, see Spam Quarantine Alias<br />

Consolidation Queries, page 3-44.<br />

The search queries you specify are available to all listeners you configure on the system.<br />

The root level of the directory is called the base. The name of the base is the DN (distinguishing name).<br />

The base DN format for Active Directory (and the standard as per RFC 2247) has the DNS domain<br />

translated into domain components (dc=). For example, example.com's base DN would be: dc=example,<br />

dc=com. Note that each portion of the DNS name is represented in order. This may or may not reflect<br />

the LDAP settings for your <strong>configuration</strong>.<br />

OL-25137-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!