Issue with LDAP Filter Configuration

Hi there,  as we know the LDAP sync in CUCM can only working with maximum 5 OU,  we try to use the utilize the LDAP Filter to work around but expeirence a bit problem.

there are dozens sites in OU AU we would like to import to CUCM, the Object DN looks like:

OU=Employees,OU=Users,OU=Sydney,OU=AU, _AccountObiects,DC=ABCD,DC=LOCAL

OU=Employees,OU=Users,OU=Melbourne,OU=AU, _AccountObiects,DC=ABCD,DC=LOCAL

OU=Employees,OU=Users,OU=Perth,OU=AU, _AccountObiects,DC=ABCD,DC=LOCAL

OU=Employees,OU=Users,OU=Brisbane,OU=AU, _AccountObiects,DC=ABCD,DC=LOCAL

... ....

We plan to sync on the top level of the AD, the LDAP user search base looks like:  _AccountObiects,DC=ABCD,DC=LOCAL

Now within the __AccountObiects, you can see, there are lot of sites and country, in order to just pull info from Australia sites. LDAP Filter has been created as following:  (OU=Employees,OU=Users,OU=Sydney) (OU=Employees,OU=Users,OU=Melbourne)  and apply this filter to the LDAP directory sync. but the problem is nothing been pulled over...

I have tested by trying to pull a user only, it is working fine. details as following:

Lobject DN:  OU=Employees,OU=Users,OU=Auckland,OU=NZ, _AccountObiects,DC=ABCD,DC=LOCAL

Filter:  (sAMAccountName=paderson)

Any suggestions? 

Thanks in advance. 


If you are just trying to selectively permit access to multiple OUs, I would consider pointing the CUCM config at OU=AU, _AccountObiects,DC=ABCD,DC=LOCAL, and the 'deny' read access to the CUCM sync account to the OUs that you don't want to be read.

I think your problem with the filter is that you aren't applying a proper attribute=value test. OU=Empl,OU=Users,OU=Syndey doesn't match three OU attributes. That string is actually a partial match on the objects relative DN. Best thing to do is inspect the objects themselves (e.g. the users) in ADSIEdit.msc to view what attributes are populated with what, and filter on those.

Aaron Harrison

Principal Engineer at Logicalis UK

Hi Aaron,  thanks for quick reply.  there is typo in my initial post,  actually the one configured is with OU=AU as following:


(OU=Employees,OU=Users,OU=Sydney,OU=AU) (OU=Employees,OU=Users,OU=Melbourne,OU=AU)

I did check the object tab in employee OU... ... it is correct in CUCM LADP configue and Filter configure page...



Aaron as usual great post...Can you help have a look at this thread...

Just want your thoughts..Thanks

