cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1021
Views
0
Helpful
1
Replies

LDAP Realm base and group DN

Madura Malwatte
Level 4
Level 4

FTD and FMC version 6.4.0.

For LDAP Realm integration is there any security concerns with having the base and group DN set to base of the directory tree - example: "dc=company,dc=com,dc=au"?

 

I have users in a few OU's under the base DN "dc=company,dc=com,dc=au", so instead of duplicating the config and having multiple realms, can I just have one realm with base and group DN as "dc=company,dc=com,dc=au", so it will cover all users that are in different OU's?

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

I generally configure the realm using DN closest to the base. Generally your device will be able to move down the tree as needed.

Review Cisco Networking for a $25 gift card