27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3-36<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

Chapter 3 LDAP Queries<br />

Figure 3-21 Configuring the LDAP Query Settings for an LDAP SMTP Authentication Profile<br />

Step 4 Select the LDAP query you would like to use for this authentication profile. Select a default encryption<br />

method from the drop-down menu. You can select from SHA, Salted SHA, Crypt, Plain, or MD5. If your<br />

LDAP servers prefix an encrypted password with the encryption type, leave ‘None’ selected. If your<br />

LDAP server saves the encryption type as a separate entity (OpenWave LDAP servers, for example), then<br />

select an encryption method from the menu. The default encryption setting will not be used if the LDAP<br />

query is using bind.<br />

Step 5 Click the Finish button.<br />

Step 6 Click the Commit Changes button, add an optional comment if necessary, and then click Commit<br />

Changes to finish adding the LDAP SMTP Authentication profile.<br />

After creating the authentication profile, you can enable the profile on a listener. See Enabling SMTP<br />

Authentication on a Listener, page 3-36 for more information.<br />

Enabling SMTP Authentication on a Listener<br />

After using the Network > SMTP Authentication page to create an SMTP authentication “profile” that<br />

specifies the type of SMTP authentication you want to perform (LDAP-based or SMTP<br />

forwarding-based), you must associate that profile with a listener using the Network > Listeners page<br />

(or the listenerconfig command).<br />

Note An authenticated user is granted RELAY connection behavior within their current Mail Flow Policy.<br />

Note You may specify more than one forwarding server in a profile. SASL mechanisms CRAM-MD5 and<br />

DIGEST-MD5 are not supported between the Cisco <strong>IronPort</strong> appliance and a forwarding server.<br />

In the following example, the listener “InboundMail” is edited to use the SMTPAUTH profile configured<br />

via the Edit Listener page:<br />

OL-25137-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!