cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
569
Views
10
Helpful
3
Replies

WebVPN (clientless) + Windows Auth

satishcp
Level 1
Level 1

Hi All,

I've configured SSLVPN on Cisco ASA 5540 to authenticate using Windows AD by providing DomainController information. Though the authentication is working, I'm bit concerned about the security as this method of authentication mechanism would expose remote access to every other account on Windows AD (including service accounts).

Is there a mecahnism / way to restrict the authenticate to specific group of users while using Windows AD for authentication on Cisco ASA for SSLVpn?

Please note: There is no ACS server available on the network.

Appreciate quick help on this,

3 Replies 3

mainesy
Level 1
Level 1

You can setup Dynamic Access Policies and configure it for a particular AD Security Group. You would need to map the LDAP memberOf field to the AD Security Group name.

Josh

Hi Josh,

Thanks for this excellent suggestion. Though would like to know if I need to enable LDAP authentication for WebUsers OR still live with Windows Auth using the following commands..

aaa-server ADdomain protocol nt

aaa-server ADdomain host 1.1.1.1

nt-auth-domain.controller dc1

Thanks

Hi,

another way might be to configure a MS IAS server on one of your Windows Servers.

Creating Remote Access policys and using the IAS as a Radius server might have a advantage that You can use it for more then just Web VPN, like perhaps 802.1x on WLANs etc.

Another would be that it might be easier to create multiple and different access policys for different AD-security groups.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806de37e.shtml

Hope this helps in some way

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: