13.07.2015 Views

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

User IdentificationNovell eDirectory replicates the attribute that uniquely identifies logged-on users onlyevery 5 minutes. Despite this replication time lag, eDirectory Agent picks up newlogon sessions as soon as a user logs on to any eDirectory replica.To configure eDirectory Agent installation to communicate with eDirectory:1. Enter the eDirectory master or replica Server IP address.2. Enter the Port that eDirectory Agent uses to communicate with the eDirectorymachine. The valid values are 389 (default) and 636 (SSL port).3. Click OK to return to the eDirectory Agent page. The new entry appears in theeDirectory Replicas list.4. Repeat the process for any additional eDirectory server machines.5. Click OK to return to the Settings > User Identification page, then click OK againto cache your changes.6. Click Save and Deploy to implement the changes.7. Stop and start eDirectory Agent so that the agent can begin communicating withthe new replica. See Stopping and starting <strong>Web</strong>sense services, page 385, forinstructions.Configuring eDirectory Agent to use LDAP<strong>TRITON</strong> - <strong>Web</strong> <strong>Security</strong> <strong>Help</strong> | <strong>Web</strong> <strong>Security</strong> Solutions | <strong>Version</strong> <strong>7.7</strong>.x<strong>Web</strong>sense eDirectory Agent can use Netware Core Protocol (NCP) or LightweightDirectory Access Protocol (LDAP) to get user logon information from NovelleDirectory. By default, eDirectory Agent on Windows uses NCP. On Linux,eDirectory Agent must use LDAP.If you are running eDirectory Agent on Windows, but want the agent to use LDAP toquery Novell eDirectory, set the agent to use LDAP instead of NCP. Generally, NCPprovides a more efficient query mechanism.To set eDirectory Agent on Windows to use LDAP:1. Ensure that you have at least one Novell eDirectory replica containing alldirectory objects to monitor and filter in your network.2. Stop the <strong>Web</strong>sense eDirectory Agent service (see Stopping and starting <strong>Web</strong>senseservices, page 385).3. Navigate to the eDirectory Agent installation directory (by default, \ProgramFiles\<strong>Web</strong>sense\bin), and then open the wsedir.ini file in a text editor.4. Modify the QueryMethod entry as follows:QueryMethod=0This sets the Agent to use LDAP to query Novell eDirectory. (The default value is1, for NCP.)5. Save and close the file.6. Restart the <strong>Web</strong>sense eDirectory Agent service.318 <strong>Web</strong>sense <strong>Web</strong> <strong>Security</strong> Solutions

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!