12-20-2007 05:39 AM - edited 03-12-2019 05:53 PM
Hi,
Does ASA 5500 support active directory ? in this i mean can i create outbound rules that authenticate users from AD ?
12-20-2007 06:45 AM
Hello,
I believe that you can use IAS service from windows server for this. ASA supports radius protocol, well it will looks like ASA->radius->AD.
12-21-2007 04:45 AM
Hi Thanks for your reply.
one question, can i install IAS on my DC ??
so that RADIUS Server will be the same as DC Server?
IF IAS is installed on a DC, will radius be able to lookup users from the AD ?
12-21-2007 05:45 AM
Hello,
Yes.
Yes.
Yes.
It's definitely works, I did the same when implement dot1x.
12-21-2007 06:01 AM
Thanks i just found this : http://support.microsoft.com/kb/317588
Will check it, and if i have any question, will report back. thanks
12-21-2007 06:16 AM
Hi,
Do u have any article on how to configure ASA 5500 to use RADIUS in its OUTBOUND rules authentication ?
12-21-2007 06:22 AM
Hello,
If you are using radius behind outside interface you have to specify it like:
ciscoasa(config)# aaa-server RADserver (outside) host 10.10.10.10
12-21-2007 06:30 AM
I want to authenticate my Internal Users, so that based on the authentication, if they go thru Rule # 1 or Rule # 2 in CISCO ASA.
In this stage, i am not intending to authenticate VPN ( Remote Users ) .
I need to authenticate Internal Users.
lets say i want to create the following rules:
rule 1 : allow> protocols> from internal > to external > groupA
rule 2 : allow> protocols> from internal > to external > groupB
is this possible ?
12-21-2007 09:15 AM
Just check this document, it's waht you need.
http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/fwaaa.html
12-21-2007 09:27 AM
mmm, i would prefer if there is an article that illustrate how to do it with the GUI ( PDM ) , as i am guy who is used to work with GUI stuff :)
Thanks will check it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide