27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 3 LDAP Queries<br />

Testing LDAP Queries<br />

OL-25137-01<br />

Microsoft Exchange environments that are aware of each other within the infrastructure can usually<br />

route mail between each other without involving a route back to the originating MTA.<br />

Use the Test Query button on the Add/Edit LDAP Server Profile page (or the test subcommand in the<br />

CLI) of each query type to test the query to the LDAP server you configured. In addition to displaying<br />

the result, AsyncOS also displays the details on each stage of the query connection test. You can test<br />

each of the query types.<br />

The ldaptest command is available as a batch command, for example:<br />

ldaptest LDAP.ldapaccept foo@ironport.com<br />

If you entered multiple hosts in the Host Name field of the LDAP server attributes, the Cisco <strong>IronPort</strong><br />

appliance tests the query on each LDAP server.<br />

Table 3-1 summarizes the testing results. (You can also use the ldaptest command.)<br />

Table 3-1 Testing LDAP Queries<br />

Query type If a recipient matches (PASS)... If a recipient does not match (FAIL)...<br />

Recipient Acceptance<br />

(Accept, ldapaccept)<br />

Routing<br />

(Routing, ldaprouting)<br />

Masquerade (Masquerade,<br />

masquerade)<br />

Group Membership (Group,<br />

ldapgroup)<br />

SMTP Auth<br />

(SMTP Authentication,<br />

smtpauth)<br />

External Authentication<br />

(externalauth)<br />

Spam Quarantine End-User<br />

Authentication (isqauth)<br />

Spam Quarantine Alias<br />

Consolidation (isqalias)<br />

Accept the message. Invalid Recipient: Conversation or<br />

delayed bounce or drop the message<br />

per listener settings.<br />

DHAP: Drop.<br />

Route based on the query Continue processing the message.<br />

settings.<br />

Alter the headers with the<br />

variable mappings defined by the<br />

query.<br />

Return “true” for message filter<br />

rules.<br />

A password is returned from the<br />

LDAP server and is used for<br />

authentication; SMTP<br />

Authentication occurs.<br />

Individually returns a “match<br />

positive” for the bind, the user<br />

record, and the user’s group<br />

membership.<br />

Returns a “match positive” for the<br />

end-user account.<br />

Returns the email address that the<br />

consolidated spam notifications<br />

will be sent to.<br />

Continue processing the message.<br />

Return “false” for message filter rules.<br />

No password match can occur; SMTP<br />

Authentication attempts fail.<br />

Individually returns a “match<br />

negative” for the bind, the user record,<br />

and the user’s group membership.<br />

No password match can occur;<br />

End-User Authentication attempts<br />

fail.<br />

No consolidation of spam<br />

notifications can occur.<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

3-17

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!