Messaging Gateway

 View Only
Expand all | Collapse all

LDAP Synchronization

  • 1.  LDAP Synchronization

    Posted Feb 10, 2009 02:12 AM

    Dear all,

    I have some problem with LDAP Synchroization. My Customer used Bynari to be mail server and he want to sync LDAP but the Directory Type in the SBG web console doesn't have bynari type. what should I do?

    I appreciate all your help and suggestions



  • 2.  RE: LDAP Synchronization

    Posted Feb 10, 2009 04:56 AM

    Hi,

     

    Only a limited number of directories are supported for Synchronization you can find details in the product manuals, however Bynari isn't one of them.  Exactly what LDAP functionality are you looking for?  Most LDAP functionality doesn't actually require LDAP Sync.  The functionality you lose with a directory that doesn't support LDAP Sync is:

     

    - The ability to create group policies based on LDAP groups

    - The ability for end users to create their own Allowed/Blocked lists from quarantine

    - The ability to silenty drop messages to invalid recipients

     

    Without LDAP Sync, you will still be able to do the following:

     

    - Give end user access to quarantine(LDAP Authentication source)

    - Reject messages to invalid recipients at connection time(Recipient Validation source)

    - Auto alias or route messages via LDAP attributes(LDAP Routing source)

    - Directory Harvest Attack(in conjunction with Recipient Validation source)

     

    Kevin



  • 3.  RE: LDAP Synchronization

    Posted Feb 11, 2009 03:53 AM

    Thanks for suggestions Kevin

     

    I already set LDAP completed, but when I tried to access to the quarantine mail by user in bynari mail.
    I could not access.

     

     



  • 4.  RE: LDAP Synchronization

    Posted Feb 11, 2009 05:11 AM

     

    Sounds like you probably have the LDAP Authentication source set up incorrectly, if you pasted up an example of one of your ldif records and a screen grab of your LDAP Authentication settings we can try to help.

     

    Kevin



  • 5.  RE: LDAP Synchronization

    Posted Feb 11, 2009 05:36 AM

    http://imagehost.thaibuzz.com/ib/bldap.jpg

     

    This my LDAP setting screen



  • 6.  RE: LDAP Synchronization

    Posted Feb 11, 2009 05:59 AM

    I think the LDAP server details look okay.  Is your test login working okay?  I would probaly put in the full DN of the user you are going to bind with, eg.'cn=manager,dc=example,dc=com'.

     

    For the Authentications Query Details, you should really be specifying a Base DN here.  If you can give the ldif extract of a typical user I can help with all the details here.  If you install a tool like Softerra LDAP browser you can look at a users ldif record and take another screen grab.

     

    Kevin



  • 7.  RE: LDAP Synchronization

    Posted Feb 11, 2009 06:01 AM

    Actually what get's returned when you test the login query?

     

    Kevin



  • 8.  RE: LDAP Synchronization

    Posted Feb 11, 2009 08:41 PM

    Might wanna check that end user settings have been enabled.

     

    You can find it under Administration -> Groups Settings -> End Users

     



  • 9.  RE: LDAP Synchronization

    Posted Feb 12, 2009 07:49 AM

    Actually End User settings will only work if LDAP Authetication and LDAP Synchronization are enabled.  As the directory in question isn't supported by LDAP Sync end user settings won't be available.

     

    One thing to point out though, after LDAP Authentication is configured correctly, the Administrator-only quarantine option needs to be unchecked on the Spam -> Settings -> Quarantine Settings page before end users will be able to login.

     

    Kevin



  • 10.  RE: LDAP Synchronization

    Posted Feb 16, 2009 11:03 AM

    Thank you for any suggestions.

     

    It works now !!!



  • 11.  RE: LDAP Synchronization

    Posted Feb 16, 2009 11:23 AM

    Great news Chai, can you let us know what you needed to do to get things working?

     

    Kevin



  • 12.  RE: LDAP Synchronization
    Best Answer

    Posted Feb 16, 2009 09:10 PM

    Dear all

    I just unchecked that you adviced me " Administrator-only " in quarantine setting after that I reboot appliance. And It can work. :)



  • 13.  RE: LDAP Synchronization

    Posted Feb 17, 2009 04:27 AM

     

    Thanks Chai,

     

    Will you mark the thread as solved.

     

    Cheers,

     

    Kevin