Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ASA & LDAP Authorization

Hello:

I have a LDAP server configured and authentication working just fine. My next goal is to provide SSL VPN services to some employees. Their Tunnel Group membership should depend upon their LDAP 'group' membership.

For example, our LDAP administrator has configured user entries like this:

dn: uid=jdoe,ou=People,o=company.com

givenName: John

sn: Doe

mail: jdoe@company.com

objectClass: top

objectClass: person

objectClass: organizationalPerson

objectClass: inetOrgPerson

objectClass: inetorgpersonsub1

uid: jdoe

cn: John Doe

description: Employee

description: Information Systems

He seems to like to use 'description' instead of OU for some reason, but that's out of my control. I assume I need to perform some sort of LDAP Attribute mapping to make this happen.

In the above example, I would like to create a Tunnel Group called 'IS' on the ASA, and if a user has 'description: Information Systems' in the ir LDAP, they would be mapped to the 'IS' tunnel group.

Can someone shed some light?

Thanks!

Mark

1 REPLY
Silver

Re: ASA & LDAP Authorization

The SSL VPN Client (SVC) is a VPN tunneling technology that gives remote users the benefits of an IPSec VPN client without the need for network administrators to install and configure IPSec VPN clients on remote computers. REfer URL for SSL VPN Servies

http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a0080565910.html

134
Views
2
Helpful
1
Replies
CreatePlease login to create content