Cisco Support Community
Community Member

Issue with LDAP Filter Configuration

Hi there,  as we know the LDAP sync in CUCM can only working with maximum 5 OU,  we try to use the utilize the LDAP Filter to work around but expeirence a bit problem.

there are dozens sites in OU AU we would like to import to CUCM, the Object DN looks like:

OU=Employees,OU=Users,OU=Sydney,OU=AU, _AccountObiects,DC=ABCD,DC=LOCAL

OU=Employees,OU=Users,OU=Melbourne,OU=AU, _AccountObiects,DC=ABCD,DC=LOCAL

OU=Employees,OU=Users,OU=Perth,OU=AU, _AccountObiects,DC=ABCD,DC=LOCAL

OU=Employees,OU=Users,OU=Brisbane,OU=AU, _AccountObiects,DC=ABCD,DC=LOCAL

... ....

We plan to sync on the top level of the AD, the LDAP user search base looks like:  _AccountObiects,DC=ABCD,DC=LOCAL

Now within the __AccountObiects, you can see, there are lot of sites and country, in order to just pull info from Australia sites. LDAP Filter has been created as following:  (OU=Employees,OU=Users,OU=Sydney) (OU=Employees,OU=Users,OU=Melbourne)  and apply this filter to the LDAP directory sync. but the problem is nothing been pulled over...

I have tested by trying to pull a user only, it is working fine. details as following:

Lobject DN:  OU=Employees,OU=Users,OU=Auckland,OU=NZ, _AccountObiects,DC=ABCD,DC=LOCAL

Filter:  (sAMAccountName=paderson)

Any suggestions? 

Thanks in advance. 


Super Bronze

Issue with LDAP Filter Configuration


If you are just trying to selectively permit access to multiple OUs, I would consider pointing the CUCM config at OU=AU, _AccountObiects,DC=ABCD,DC=LOCAL, and the 'deny' read access to the CUCM sync account to the OUs that you don't want to be read.

I think your problem with the filter is that you aren't applying a proper attribute=value test. OU=Empl,OU=Users,OU=Syndey doesn't match three OU attributes. That string is actually a partial match on the objects relative DN. Best thing to do is inspect the objects themselves (e.g. the users) in ADSIEdit.msc to view what attributes are populated with what, and filter on those.

Aaron Harrison

Principal Engineer at Logicalis UK

Please rate helpful posts...

Aaron Please remember to rate helpful posts to identify useful responses, and mark 'Answered' if appropriate!
Community Member

Issue with LDAP Filter Configuration

Hi Aaron,  thanks for quick reply.  there is typo in my initial post,  actually the one configured is with OU=AU as following:


(OU=Employees,OU=Users,OU=Sydney,OU=AU) (OU=Employees,OU=Users,OU=Melbourne,OU=AU)

I did check the object tab in employee OU... ... it is correct in CUCM LADP configue and Filter configure page...



VIP Super Bronze

Issue with LDAP Filter Configuration

Aaron as usual great post...Can you help have a look at this thread...

Just want your thoughts..Thanks

Please rate all useful posts "The essence of christianity is not the enthronement but the obliteration of self --William Barclay"
CreatePlease to create content