Reference Guide

Table Of Contents
Dell PowerConnect ArubaOS 6.0 Command Line Interface | Reference Guide aaa authentication-server ldap | 44
Syntax
Usage Guidelines
You configure a server before you can add it to one or more server groups. You create a server group for a specific
type of authentication (see “aaa server-group” on page 70).
Example
The following command configures and enables an LDAP server:
aaa authentication-server ldap ldap1
host 10.1.1.243
base-dn cn=Users,dc=1m,dc=corp,dc=com
Parameter Description Range Default
<server> Name that identifies the server.
admin-dn <name> Distinguished name for the admin user who has read/search
privileges across all of the entries in the LDAP database (the user
does not need write privileges but should be able to search the
database and read attributes of other users in the database).
——
admin-passwd
<string>
Password for the admin user.
allow-cleartext Allows clear-text (unencrypted) communication with the LDAP
server.
enabled|
disabled
disabled
authport <port> Port number used for authentication. Port 636 will be attempted
for LDAP over SSL, while port 389 will be attempted for SSL over
LDAP, Start TLS operation and clear text.
1-65535 389
base-dn <name> Distinguished Name of the node which contains the entire user
database to use.
——
clone <server> Name of an existing LDAP server configuration from which
parameter values are copied.
——
enable Enables the LDAP server.
filter Filter that should be applied to search of the user in the LDAP
database (default filter string is: ì(objectclass=*)î ).
(objectclass
=)*
host <ip-addr> IP address of the LDAP server, in dotted-decimal format.
key-attribute
<string>
Attribute that should be used as a key in search for the LDAP
server. For Active Directory, the value is sAMAccountName.
sAMAccount
Name
no Negates any configured parameter.
preferred-conn-
type
Preferred connection type.The default order of connection type
is:
1. ldap-s
2. start-tls
3. clear-text
The controller will first try to contact the LDAP server using the
preferred connection type, and will only attempt to use a lower-
priority connection type if the first attempt is not successful.
NOTE: You enable the allow-cleartext option before you select
clear-text as the preferred connection type. If you set clear-text
as the preferred connection type but do not allow clear-text, the
controller will only use ldap-s or start-tls to contact the LDAP
server.
ldap-s
start-tls
clear-text
ldap-s
timeout <seconds> Timeout period of a LDAP request, in seconds. 1-30 20 seconds