Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Single Sign On (SSO) Internet Access via ASA

Good Afternoon,

I'm looking for a way for users to authenticate through the ASA to determine whether or not they are granted access to the Internet. I would like to provide two separate Active Directory groups, for example, GRP-NO-INTERNET and GRP-INTERNET. When a user accesses the Internet I would like the firewall to obtain a SSO credential and query AD to see if they have access or not and respond accordingly.

I'm currently working with TAC to investigate the possibility of using DAP but was curious if others have successfully tested this or what other options may be available. The end result would be to eliminate the credentials prompt by the firewall and have the authentication done in the background (somehow) without user interaction.

Thanks in advance to anyone's suggestions.



Single Sign On (SSO) Internet Access via ASA

Actually, it should be possible starting ASA 8.4.2. You will have to configure an AD Agent on Windows. Please see the following link

Please rate if it helps. Kind regards

CreatePlease to create content