5.1

Table Of Contents
n
Add RSA-ACE Authentication Server on page 117
You can add an RSA-ACE authentication server to bound to the SSL gateway. All users in the bounded
authenticated server will be authenticated.
n
Add Local Authentication Server on page 118
You can add a local authentication server to bound to the SSL gateway. All users in the bounded
authenticated server will be authenticated.
Add AD Authentication Server
You can add an AD authentication server to bound to the SSL gateway. All users in the bounded authenticated
server will be authenticated.
Procedure
1 In the vSphere Client, select Inventory > Hosts & Clusters.
2 Select a datacenter resource from the inventory panel.
3 Click the Network Virtualization tab.
4 Click the Edges link.
5 Double-click a vShield Edge instance.
6 Click the VPN tab.
7 Click the SSL VPN-Plus tab.
8 In the Configure panel, click Authentication.
9
Click the Add (
) icon
The Add Server dialog box opens.
10 In Type, select AD.
11 Type the IP address of the external server.
12 Type the port number for the AD server.
13 Select Enable SSL to enable the SSL service on the specified server.
14 In Timeout Period, type the period in seconds within which the AD server must respond.
15 Select Enabled or Disabled to indicate whether the server is enabled.
16 Type the search base to indicate the part of the external directory tree to search.
The search base may be something equivalent to the organization, group, or domain name (AD) of external
directory.
17 Type the bind DN.
Bind DN is the user on the external AD server permitted to search the AD directory within the defined
search base. Most of the time, the bind DN is permitted to search the entire directory. The role of the bind
DN is to query the directory using the query filter and search base for the DN (distinguished name) for
authenticating AD users. When the DN is returned, the DN and password are used to authenticate the
AD user.
18 Type the bind password to authenticate the AD user.
19 Retype the bind password.
20 In Login attribute name, type the name against which the user ID entered by the remote user is matched
with.
For Active Directory, the login attribute name is sAMAccountName.
Chapter 9 vShield Edge Management
VMware, Inc. 115