Skip to main content

LDAP Preferences

FileWave supports connecting youran LDAP networkdirectory, directorysuch as Active Directory, Open Directory, or eDirectory –eDirectory, to your FileWave Server. ThisFileWave capabilitycan providesuse access tothat directory information for use in Smart Groups and parameterized profiles. YouLDAP can also usebe LDAPused for enrollment authentication.authentication, Usingwhich LDAP to authenticate your devices giveslets you atrack way to know who (which LDAP user)user enrolled whata device.

Creating an LDAP server entry in Preferences

NpvWrgvjjkbJ88ZX-embedded-image-opsacxcb.pngNpvWrgvjjkbJ88ZX-embedded-image-opsacxcb.png

Use the [+] button to create a newan LDAP server entryentry, andthen enter the needed connection information as described below:details:

  • Name - a reference name usedyou by youuse to differentiate yourtell LDAP servers apart
  • Host / IP - enter either athe FQDN or IP address forof yourthe LDAP server
  • Port - enter the TCP port requiredFileWave should use to accessreach yourthe LDAP server (you may need toserver; check with your network support)team if you are not sure
  • Protocol – select LDAP, LDAPS, or STARTSSL. 
    • For LDAPS and STARTSSL you have a checkbox that you can potentially uncheck so thatSTARTSSL, the Check Server Certificate option controls whether FileWave checks the LDAP server certificate is not checked against the machine'computer's trust store.

IFFor LDAPS or STARTSSLSTARTSSL, it is recommended to be usinguse a trusted LDAP cert.certificate whenever possible.

  • Server Type - choose Active Directory, Open Directory, or eDirectory
  • Base DN - enter the primary distinguished namesname (DN) for yourthe LDAP serverserver, using the domain components separated by commas. For example, ifIf the LDAP server is running on the same boxsystem as the FileWave server,Server, yourthe baseBase DN may be as simple as "dc=home,dc=local";local. but ifIf the LDAP server is running on a differentanother system, the value of the base DNit may be involve usinguse a more extendedspecific value,value such as "dc=tanner,dc=filewave,dc=net"net.
  • LDAP User DN - if you are doingfor authenticated binds to your LDAP server, you will need tobinds, enter a valid user account that hasis beenallowed designatedto bind to the LDAP server. Leave this blank for binding. If you are doing anonymous binding, this entry is left blank.binds.
  • LDAP User Password - enter athe password to completefor the authenticatedLDAP bind;bind account; not needed for anonymous binds
  • Refresh Interval (sec) - enterhow a valueoften, in seconds forseconds, the FileWave Server to contactcontacts the LDAP server to refresh the available data. IfDuring yousetup areand just setting uptesting, a FileWaveshort serverinterval onsuch as 120 seconds can be useful. In production, a network with an established LDAP server, you should set the24-hour interval relativelyis shortusually (~120safer: seconds) while you are testing and making changes. Once you go into production mode, you should change the interval to 24 hr. (86,400 seconds).seconds.
  • Change Limit (%) - LDAPprevents LDAP-related items willfrom not bebeing removed ifwhen more than the givenspecified percentage of the items disappeardisappears after a sync. This isprotects toFileWave avoidfrom losslarge ofunintended dataremovals ifcaused somethingby goesa wrong with thebad LDAP configuration.

IfFor forexample, exampleif ana entiremissing OU is suddenly missing that makes uprepresents 25% of yourthe LDAP directory, then the amount of change will be so large that FileWave will not initially accept thethose changesremovals if you setwhen Change Limit is set from 1% tothrough 25%,. butIf ifChange youLimit had itis set to 26%, itFileWave wouldcan accept that removal. When considering theThe next optionsetting, inRemove conjunctionMissing withitems this itafter, can still takerequire X amount ofmultiple syncs forbefore removals to occur. 

  • Remove Missing items after - 0 means records that recordsare notno longer found in the LDAP server,LDAP, but are still present in FileWaveFileWave, will beare removed immediately. 

SettingFor itsafety, set this to a number that isvalue equivalent to 24 hrs is recommended for safety.hours.

(Refresh Interval / 60(second60 to min)seconds / 60(min60 to hrs))minutes) * x = 24(hrs)24 hours

SoFor ifa I wanted anrefresh interval of 1800 secondsseconds, (30min),or I30 wouldminutes, set mythis intervalvalue to 4848.

Enable Automatic Group updates for this LDAP creates a visible set of entries (Smart Groups)Groups in the Clients pane under an LDAP designator. TheseFileWave updates these Smart Groups will be updated by FileWave at the designatedconfigured refresh intervalinterval.
The LDAP information providedshown in the Clients pane for LDAP is a one-way view of yourthe directory server. While changesChanges made aton the LDAP server are automatically reflected in FileWave;FileWave, but changes made in FileWave AdminCentral do not affectchange the LDAP directory information.directory.

Choosing to enable the automaticAutomatic Group updates createscan aput visible set of entries in the Clients pane of FileWave Admin, and keeps that information up to date; however, for an LDAP environment of over a few hundred records, theheavy load on the LDAP server canin getenvironments extremelywith heavy.more than a few hundred records. Enable it deliberately and watch LDAP server performance after the first sync.


The Test Connection button pingschecks whether the server tois seeonline, ifbut it is online; but does not verify allevery connectionLDAP settings.setting. You should always useUse an LDAP browser tool to verify the linkdirectory topath yourand server.bind account before relying on the configuration.
You can create entries for multiple LDAP servers,servers. and anAn LDAP server can bealso runningrun on the same device or VM as the FileWave Server.

An LDAP server can be chosen as the Authentication server. which,In in thisthat case, meansFileWave uses that the directory for that server will be used for profiles that support parameterized settings. Selecting the use it for extraction setting adds the directory information to the FileWave database. You can view the LDAP settings in theAssistants Assistants/> LDAP Browser in FileWave Admin.Central.

AtThe Synchronize Now option at the Bottom bottom-right of the LDAP server pane,pane there is a Synchronize Now option. This option will allowlets you to synchronize all your LDAP servers, justone one,LDAP server, or synconly LDAP Custom Fields. 

iuX9yMsywqtsn5iS-embedded-image-djfbjkt1.pngiuX9yMsywqtsn5iS-embedded-image-djfbjkt1.png