The target of the subscriber classification script is an LDAP search string. The search string uses a syntax similar to an LDAP URL (see RFC 2255—The LDAP URL Format (December 1997).
The syntax is:
![]() |
Note: You can use subscriber classification to override only the ipAddress, loginName, or accountingId attributes. If you configure values to override other attributes, the value is lost when the SAE recovers from a network or server failure. |
With the exception of baseDN all the fields are optional.
The result of the LDAP search must be exactly one directory object. If no object or more than one object is found, the subscriber session is terminated.