ASA DAP LDAP Inheritance ?

Unanswered Question
Dec 4th, 2009
User Badges:

Is there any way, maybe through LUA script to check for membership in nested groups?

IE a user is directly a memeber of "Location Employees"

"Location Employees" is a memeber of  "Company Employees"

Making the rule allow anyone that is a member of "Company Employees" pass?

At the moment I can get around some of this by using LUA to match on groups ENDING in Employees but I have other cases that would work better. The only alternative I see is to create a bunch of new groups and make the users direct memebers.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Ivan Martinon Tue, 12/08/2009 - 15:41
User Badges:
  • Cisco Employee,

Hi, there is a feature request for this, currently it is not supported

CSCso24147 VPN RA Active Directory/LDAP  Nested-Groups Support




This Discussion