Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
New Member

LDAP Query for OU membership?

We have 100+ OUs that our users are broken into. I am trying to configure a LDAP group query that will test for membership of an OU. I can test using memberof successfully using the DN of that distribution/security group but some of our users are not in any distribution or security groups, they are just users in an OU. Does anyone have any advice on how I can do this?

2nd question:
Does IronPort support wildcard ldap lookups?


New Member

Re: LDAP Query for OU membership?

Hello JMeyer,

I found an URL explaining how to do such queries:

To simplify your query development you can use a LDAP browser to test your queries without having to edit your Ironport config over and over.
I personally like the Apache LDAP studio browser/editor very much. it's free and rich. Another good one is the Softera LDAP browser. (Also free, the browser/editor is commercial)

By the way: make sure you are querying properly indexed fields! if you use un-indexed fields your performance may drop dramatically. Most LDAP servers allow you to add indexes if one is missing, please use your LDAP server manual to find out what is the best way to do this.

Good luck!


New Member

Re: LDAP Query for OU membership?

Thanks for the input Steven this helps me.

If anyone else has any input on advanced LDAP queries and how to build them with IronPort I would be very interested in seeing what can all be done.