Mirroring an LDAP server

Prev Next

LDAP server mirroring to the ePO - On-prem database increases performance on any product which uses user-based policies (UBP) and allows LDAP access to Agent Handlers behind a DMZ.

This diagram shows the default LDAP server to Agent Handler connection process and the mirrored LDAP connection process.

  1. Default connection process from the configured LDAP server to the Agent Handler.

  2. Mirrored LDAP connection with the LDAP Synchronize server task requesting user information from the LDAP server.

  3. Shows the LDAP server user information mirrored to the ePO - On-prem database.

  4. Shows an Agent Handler behind the DMZ accessing the mirrored LDAP server information in the ePO - On-prem database.

Default and LDAP mirrored connection processes
Default and LDAP mirrored connection processes


Why use LDAP mirroring?

When the LDAP server user information is mirrored to the ePO - On-prem database:

  • Medium to large organizations can access that user information used by the Agent Handler from the database faster to satisfy LDAP requests for UBPs.

  • Agent Handlers behind a DMZ can access the LDAP user information.

Note

The LDAP information in the database can't be accessed or queried from the ePO - On-prem user interface.

By default, the LDAP information in the database is updated every 8 hours by the LdapSync: Sync across users from LDAP server task unless:

  • An "LDAP change notification" is sent to the Agent Handler from the ePO - On-prem server.

    Note

    By default, the LDAP user information cache in the Agent Handler is updated every 30 minutes.

  • You manually run the server task.