cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1116
Views
0
Helpful
2
Replies

Dynamic Access Policies with RSA Authentication

Brent Catoe
Level 1
Level 1

What is the best way to use DAP when using RSA for user authentication. I really do not want to have the users have to authenticate twice, once for tunnel authentication through RSA and then again for AD authentication. Is there a way to add users to groups on the RSA server and apply policies based on those groups?


Thanks

2 Replies 2

Erick Delgado
Level 1
Level 1

Hi,

You want to do group mapping with RSA? if yes please see the following documentation.

Yopu can authenticate against RSA and authorize using LDAP.

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMap.html

Regards,

I have a similar request ... I'm trying to setup DAP for two different AAA groups.  The first group (vendors) is authenticated to Windows Active Directory using LDAP and I check for a "member of" AAA attribute to define which DAP to apply.  This works correctly.

However, the second group (employees) is passed off to RSA using the SDI protocol, because our employees use tokens.  The DAP check for "member of" doesn't work.  It seems like RSA doesn't return the "member of" attribute ... or if it does, the ASA doesn't receive it.  Is it possible to use DAP for RSA authentication?  If so, how do you setup the AAA attributes?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: