27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 3 LDAP Queries<br />

OL-25137-01<br />

Step 2 Set Active Directory Permissions<br />

– Open ADSIEdit form the Windows 2000 Support Tools.<br />

– Locate the Domain Naming Context folder. This folder has the LDAP path of your domain.<br />

– Right click the Domain Naming Context folder, and then click Properties.<br />

– Click Security.<br />

– Click Advanced.<br />

– Click Add.<br />

– Click the User Object Everyone, and then click OK.<br />

– Click the Permission Type tab.<br />

– Click Inheritance from the Apply onto box.<br />

– Click to select the Allow check box for the Permission permission.<br />

Step 3 Configure the Cisco <strong>IronPort</strong> Messaging Gateway<br />

Use ldapconfig on the Command Line Interface (CLI) to create an LDAP server entry with the<br />

following information.<br />

– Hostname of an Active Directory or Exchange server<br />

– Port 3268<br />

Anonymous Bind Setup for Active Directory<br />

User Object Permissions Inheritance Permission Type<br />

Everyone Read Public Information User Objects Property<br />

Everyone Read Phone and Mail<br />

Options<br />

User Objects Property<br />

– Base DN matching the root naming context of the domain<br />

– Authentication type Anonymous<br />

The following setup instructions allow you to make specific data available to anonymous bind queries<br />

of Active Directory and Exchange 2000 servers in the Microsoft Windows Active Directory. Anonymous<br />

bind of an Active Directory server will send the username anonymous with a blank password.<br />

Note If a password is sent to an Active Directory server while attempting anonymous bind, authentication may<br />

fail.<br />

Step 1 Determine required Active Directory permissions.<br />

Using the ADSI Edit snap-in or the LDP utility, you must modify the permissions to the attributes<br />

of the following Active Directory objects.<br />

– The root of the domain naming context for the domain against which you want to make queries.<br />

– All OU and CN objects that contain users against which you wish to query email information.<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

3-15

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!