LDAP Server Settings

Table 1. Settings for LDAP servers
Setting Description
Name Type a Name for the new or cloned server.
LDAP Server Select an IP Address or Host Name from the Select menu, or select Add.
Description (Optional)

Although optional, entering a description is helpful for troubleshooting and for identifying the server.

RADIUS User Base DN Type the RADIUS user base distinguished name, or the starting point for directory server searches, such as cn=visitors, and the point in the directory tree structure under which the server stores user accounts in its database.
Note: ExtremeCloud‌ IQ supports up to 2000 users per user group. For more than 2000 users, you must separate the users into different user groups.
Bind DN Name Type the LDAP client distinguished name used during the authentication part of an LDAP session, such as cn=users, cn=students, dc=southamerica, ou=student, and ou=school.
Bind DN Password Type the password for the LDAP client distinguished name for use during the authentication part of an LDAP session.
Show Password Select Show Password to see the password.
Communication Select LDAP or LAPDS for the required communication protocol.
Optional Settings
Filter Attribute Enter required Filter Attribute for searching for elements below the baseObject.
Strip realm name from filter Select the check box to disable the realm, which is commonly appended to a user name and delimited with an @ sign, from the filter.
Destination Port (Required)

Enter the LDAP server Destination Port.

TLS Authentication/Encryption Select the check box to enable Transport Layer Security authentication and encryption, and configure the settings.
TLS Authentication/Encryption
CA Certificate File (Required)

Select the default certification authority digital certificate type from the list.

LDAP Client Certificate (Required)

Select the default LDAP client digital certificate type from the list.

Client Key File (Required)

Select the default client key digital certificate type from the list.

Key File Password Type the client key file password.
Show Password Select the check box to see the password.
Verify Server Choose how often the Extreme Networks device checks the relationship between a certificate and its server:
  • Try (on first authorization or authentication)
  • Never
  • Demand (as required, on demand)