Page 496 / 794 Scroll up to view Page 491 - 495
Vigor2860 Series User’s Guide
482
8.
Check
Enable UDP Bandwidth Control
on the bottom to prevent enormous UDP traffic
influence other application. Click
OK
.
9.
If the worker has connected to the headquarter using host to host VPN tunnel. (Please
refer to Chapter 3 VPN for detail instruction), he may set up an index for it. Enter the
Class Name of Index 3. In this index, he will set reserved bandwidth for 1 VPN tunnel.
10.
Click
Edit
for Class 3 to open a new window. In this index, the user will set reserved
bandwidth for
VPN
.
Page 497 / 794
Vigor2860 Series User’s Guide
483
11.
Click
Add
to open the following window. Check the
ACT
box, first.
12.
Then click
Edit
of
Local Address
to set a worker’s subnet address. Click
Edit
of
Remote Address
to set headquarter’s IP address. Leave other fields and click
OK
.
Page 498 / 794
Vigor2860 Series User’s Guide
484
4.6 How to Implement the LDAP/AD Authentication for User
Management?
For simplifying the configuration of LDAP authentication for User Access Management, we
implement “Group” feature.
There is no need to pre-configure user profile for each user on Vigor router anymore. We only
need to configure the Groups DN, then the Vigor router (e.g., Vigor 2860 series) can pass the
authentication to LDAP server with the pre-defined Group path.
Below shows the configuration steps:
1.
Access into the web user interface of the Vigor router.
2.
Open
Applications>>Active Directory /LDAP
to get the following page for
configuring LDAP related settings.
There are three types of bind type supported:
Simple
Mode
– Just simply do the bind authentication without any search action.
Anonymous
– Perform a search action first with Anonymous account then do the
bind authentication.
Regular
Mode
– Mostly it is the same with anonymous mode. The different is that,
the server will firstly check if you have the search authority.
For the regular mode, you’ll need to type in the
Regular DN
and
Regular
Password
.
3.
Create LDAP server profiles. Click the
Active Directory /LDAP
tab to open the profile
web page and click any one of the index number link.
If we have two groups “
RD1
” and “
SHRD
” on LDAP server, we can configure two
LDAP server profiles with different Group Distinguished Name.
Page 499 / 794
Vigor2860 Series User’s Guide
485
and
4.
Click
OK
to save the settings above.
5.
Open
User Management>>General Setup.
Select
User-Based
as the
Mode
option.
Page 500 / 794
Vigor2860 Series User’s Guide
486
6.
Then open
VPN and Remote Access>>PPP General Setup
to
check
the profile(s) that
will be authenticated with LDAP server.
7.
After above configurations, users belong to either “rd1” or “shrd” group can access
Internet after inputting their credentials on LDAP server.

Rate

4.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top