Windows Server 2012 R2
■
Prerequisite software
Active Directory
■
Authentication protocol for user for searching
LDAP v3 simple bind
■
Note:
When using an LDAP server or a Kerberos server as an authentication server,
and combining it with an authorization server, use the same host for the
authentication and authorization servers.
When a RADIUS server is used as an authentication server, two
authentication servers (one primary and one secondary) can be specified, but
only one authorization server can be specified.
Connecting two authentication servers
Two authentication servers can be connected to a storage system. When the servers are
connected, the server configurations must be the same, except for the IP address and
the port.
If you search for a server using information registered in the SRV records in the DNS
server, confirm that the following conditions are satisfied:
Note: For RADIUS servers, you cannot use the SRV records.
LDAP server conditions:
The environmental setting for the DNS server is completed at the LDAP server.
■
The host name, the port number, and the domain name of the LDAP server are
■
registered in the DNS server.
Kerberos server conditions:
The host name, the port number, and the domain name of the Kerberos server
■
are registered in the DNS server.
Because UDP/IP is used to access the RADIUS server, no encrypted communications are
available, such as negotiations between processes. To access the RADIUS server in a
secure environment, encryption in the packet level is required, such as IPsec.
Connecting authentication and authorization servers
To use an authentication server and an authorization server, you must create
configuration files and configure your network. Detailed setting information is required
for the authentication server and the authorization server, especially for creating a
configuration file.
System Administrator Guide for VSP Gx00 models and VSP Fx00 models
Chapter 5: Setting up security
Connecting two authentication servers
159