27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

3-40<br />

Figure 3-25 Adding an Outgoing SMTP Route<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

Chapter 3 LDAP Queries<br />

Step 4 Click the All Other Domains link. The Edit SMTP Route page is displayed. Enter the name of the<br />

Destination Host for the SMTP route. This is the hostname of your external mail relay used to deliver<br />

outgoing mail.<br />

Step 5 Select the outgoing SMTP authentication profile from the drop-down menu. Click the Submit button<br />

Step 6 Commit your changes.<br />

Logging and SMTP Authentication<br />

The following events will be logged in the Cisco <strong>IronPort</strong> mail logs when the SMTP Authentication<br />

mechanism (either LDAP-based, SMTP forwarding server based, or SMTP outgoing) is configured on<br />

the appliance:<br />

[Informational] Successful SMTP Authentication attempts — including the user authenticated and<br />

the mechanism used. (No plaintext passwords will be logged.)<br />

[Informational] Unsuccessful SMTP Authentication attempts — including the user authenticated<br />

and the mechanism used.<br />

[Warning] Inability to connect to the authentication server — including the server name and the<br />

mechanism.<br />

[Warning] A time-out event when the forwarding server (talking to an upstream, injecting Cisco<br />

<strong>IronPort</strong> appliance) times out while waiting for an authentication request.<br />

Configuring External Authentication for Users<br />

You can configure the Cisco <strong>IronPort</strong> appliance to use an LDAP directory on your network to<br />

authenticate users by allowing them to log in with their LDAP usernames and passwords. After you<br />

configure the authentication queries for the LDAP server, enable the appliance to use external<br />

authentication on the System Administration > Users page in the GUI (or use the userconfig command<br />

in the CLI).<br />

To configure external authentication for users, complete the following steps:<br />

Step 1 Create a query to find user accounts. In an LDAP server profile, create a query to search for user<br />

accounts in the LDAP directory.<br />

Step 2 Create group membership queries. Create a query to determine if a user is a member of a directory<br />

group.<br />

Step 3 Set up external authentication to use the LDAP server. Enable the appliance to use the LDAP server<br />

for user authentication and assign user roles to the groups in the LDAP directory. For more information,<br />

see “Adding Users” in the Cisco <strong>IronPort</strong> AsyncOS for Email Daily Management Guide.<br />

OL-25137-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!