Skip to main content
Version: 2026.09

LDAP server

This is step 3 of the setup wizard (optional). It is needed for signing in to the web console with Active Directory accounts and for reporting by Active Directory group. Later you can open it from the Setting management menu.

The minimum you need​

In most environments these fields are enough; the other fields come with ready values for Active Directory.

FieldExample
AliasNascella AD — the name shown in lists
Primary server192.168.139.2 or the domain controller's name
LDAP base DNdc=nascella,dc=local
Port389
Username / PasswordAn LDAP account that can search the directory

LDAP server: general settings, security, flags and attributes

Add more domain controllers in Secondary server and Third server.

Flags and behaviors​

OptionDefaultDescription
Use ping for server alive checkOnPings the server before connecting.
OpenLDAPOffTurn on if the directory is OpenLDAP rather than Active Directory.
LDAP SSL requiredOffUses an encrypted connection (LDAPS).
Validate certificateOffValidates the server certificate over LDAPS.
User search requiredOffAt sign-in the user is first looked up with the LDAP account above to find their DN, then verified with that DN. When off, the user is verified directly with the name they typed.
Load balanceOffSpreads requests across the defined servers.
Group checkOffAt sign-in, checks the user's group membership against Allowed groups.
Using SSL

Turn on LDAP SSL required and change the port accordingly (usually 636 for LDAPS). If certificate validation is on and the server certificate is issued by your corporate certificate authority, you may need to upload that authority's certificate under Trusted Certificates.

Attributes and mapping​

These come ready for Active Directory; change them only if your directory is structured differently.

FieldDefault
Netbios nameThe short domain name, for example nascella
Login attributesAMAccountName
Mobile attributemobile
Group attributeGroup
All user attributesAttributes read for each user (C, CN, COMPANY, DEPARTMENT, DISPLAYNAME…)
User search attributes(&(sAMAccountType=805306368)(|(mail=*%userinput%*)(sAMAccountName=*%userinput%*)(dn=*%userinput%*)))
Custom attribute 1–5Extra attributes you want to read

Filters and access control​

Filters and access control, trusted certificates and test area

FieldDescription
All user search filterDefault (&(sAMAccountType=805306368)) — user accounts only.
Allowed groups / Blocked usersLimit to specific groups or leave specific users out.
Allowed OU filterReads objects and users only from the OUs you select.
Denied OU filterLeaves out the OUs you select and looks at the rest.

Test and save​

After filling in the fields, verify them in the LDAP test area at the bottom before saving.

  1. Under Connection Test, click Ldap Connection Test.
  2. Result should show Status: Success. Show data opens the returned data, Show Logs the detailed logs.
  3. You can also use the Login and Search sections to check that a user can sign in and be found.
  4. Click Save.
Test before you save

The test uses the values currently on the screen, even if they are not saved yet; try a change first, then save it.

LDAP connection test succeeded

Next step​

Click Continue setup to return to the wizard; the LDAP Server step shows as Completed.

LDAP Server completed

Next step: GeoIP.