
Managing Accounts and Domains 79
SMTP over TLS/SSL settings If SMTP over TLS/SSL is enabled then passwords will not be sent in
clear text if both sending and receiving systems support TLS/SSL. If
one system does not support TLS/SSL, then traffic between the
systems will not be secured/encrypted.
If you enable this option and an LDAP connection cannot be made or
the StartTLS LDAP command is not supported or disallowed, then the
LDAP connection fails.
LDAP Port The LDAP port used to communicate with the Exchange server. By
default, this port is 389.
LDAP / Exchange Username The username for the LDAP/Exchange server.
To determine the fully-qualified username, open Active Directory, go
into Active Directory Users and Computers and double-click on the
user account in question. Under the Account tab, use the User Login
Name plus the @xxx.xxx that follows as the LDAP username.
LDAP / Exchange Password The password for the LDAP/Exchange server.
LDAP Filter The custom LDAP filter to apply to this domain (optional).
LDAP Search Base The starting search point in the LDAP tree. The default value looks up
the 'defaultNamingContext' top-level attribute and uses it as the
search base.
If you have two domains under one forest, and you want to
authenticate both domains using the same LDAP server, use an
LDAP search base of DC=com and LDAP port of 3268. This allows
for a complete search under the .com domain and a Global Catalog
default connection.
LDAP UID
This specifies an attribute of the LDAP container found using the
LDAP filter and which provides the Barracuda a unique identifier
to associate with user accounts on the Barracuda. This is
primarily used for Alias Unification and Single-signon. Typically
this is uid, or on more recent Active Directory schemas
sAMAccountName.
LDAP Primary Email Alias
When Unify Email Aliases is enabled this LDAP container
attribute provides the account name under which quarantined
messages are stored and for which the actual recipient address is
an alias of. For Single-Signon using LDAP (and when Unify
Email Aliases is enabled), this is the account that users will be
directed to when logging in with any of their aliases. This
attribute is almost always mail, and should be a fully qualified
address with a local part, an "@" sign, and a domain component
which is configured on the Barracuda as a valid domain.
Canary Email
This email address is used to determine if LDAP lookups are
properly locating valid and invalid email addresses for this
domain during the normal operation of the Barracuda. If at
anytime the provided canary address is not found in the LDAP
directory then LDAP recipient verification (Exchange
Accelerator) and Unify Email Aliases will be disabled for the
duration of the failure.
Table 6.5:
Komentarze do niniejszej Instrukcji