When configuring an LDAP Group object, select option _______________ if you want the gateway
to reference a specific group defined on the LDAP server for authentication purposes.
A.
Group Agnostic
B.
All Account-Unit’s Users
C.
Only Sub Tree
D.
Only Group in Branch
D)
Only Group in Branch
from student manual
Check the LDAP group objects configuration.
All Account·
Unit’s Users or Only Sub Tree · the groups defined on the LDAP server are irrelevant
Only Group in branch· the group must point to a group on the LDAP server.
SRC: https://sc1.checkpoint.com/documents/R80/CP_R80_SecMGMT/html_frameset.htm?topic=documents/R80/CP_R80_SecMGMT/118981‘
To create LDAP groups for User Directory:
In SmartConsole, open Object Categories > New > More > Users > LDAP group.
In the New LDAP Group window that opens, select the Account Unit for the User Directory group.
Define Group’s Scope – select one of these:
All Account-Unit’s Users – All users in the group
Only Sub Tree – Users in the specified branch
Only Group in branch – Users in the branch with the specified DN prefix
Apply an advanced LDAP filter:
Click Apply filter for dynamic group.
Enter the filter criteria.
It seems should be “D”.
Click OK.
C. Only Sub Tree
D. Only Group in Branch