Configuring profiles : Configuring LDAP profiles : Configuring advanced options
Configuring advanced options
The following procedure is part of the LDAP profile configuration process. For general procedures about how to configure an LDAP profile, see “Configuring LDAP profiles”.
1. Go to Profile > LDAP.
2. Click New to create a new profile or double click on an existing profile to edit it.
3. Click the arrow to expand the Advanced Options section.
4. Configure the following:
 
GUI item
Description
Timeout
Enter the maximum amount of time in seconds that the FortiMail unit will wait for query responses from the LDAP server.
Protocol version
Select the LDAP protocol version used by the LDAP server.
Enable cache
Enable to cache LDAP query results.
Caching LDAP queries can introduce a delay between when you update LDAP directory information and when the FortiMail unit begins using that new information, but also has the benefit of reducing the amount of LDAP network traffic associated with frequent queries for information that does not change frequently.
If this option is enabled but queries are not being cached, inspect the value of TTL. Entering a TTL value of 0 effectively disables caching.
TTL
Enter the amount of time, in minutes, that the FortiMail unit will cache query results. After the TTL has elapsed, cached results expire, and any subsequent request for that information causes the FortiMail unit to query the LDAP server, refreshing the cache.
The default TTL value is 1440 minutes (one day). The maximum value is 10080 minutes (one week). Entering a value of 0 effectively disables caching.
This option is applicable only if Enable cache is enabled.
Enable webmail password change
Enable if you want to allow FortiMail webmail users to change their password.
Password schema
Select your LDAP server’s user schema style, either Openldap or Active Directory.
Bypass user verification if server is unavailable
If you have selected using LDAP server to verify recipient or sender address and your LDAP server is not accessible, enabling this option will bypass the address verification process.
For more information about recipient address verification, see “Configuring recipient address verification”.