Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Active Directory Authentication

Hello,

Currently, to allow staff to access restricted websites from the internet, I obtain their home IP address and enable an access rule to allow them to access that website.  Unfortunately, their home IP addresses are dynamic and change periodically.  I'm looking into allowing them access through my ASA based on their Active Directory credentials.

Under Identity Options in ASDM, I added an entry for my DC and when I click Test and enter credentials, the test is successful.  So, under Access Rules, I modify the rule to allow any access from the internet, but I add certain users from AD.  It doesn't work, however.

I'm not sure what I'm missing.  I looked at the Identity Firewall documentation, but I'm not sure I need an AD Agent, it doesn't seem to be what I need for this scenario.  Does anyone have any ideas or a link they can point me to?  I have been searching, but I can't seem to find what I'm looking for.

Thanks in advance!

Everyone's tags (1)
1 ACCEPTED SOLUTION

Accepted Solutions

Active Directory Authentication

Hello,

Yes, you will need the AD agent to run Identity Firewall.

You could also use Cut-Through Proxy for HTTP/HTTPS traffic and using LDAP for the authentication part.

That should do it bud.

Rate all of the helpful posts!!!

Regards,

Jcarvaja

Follow me on http://laguiadelnetworking.com

Looking for some Networking Assistance? Contact me directly at jcarvaja@laguiadelnetworking.com I will fix your problem ASAP. Cheers, Julio Carvajal Segura http://laguiadelnetworking.com
1 REPLY

Active Directory Authentication

Hello,

Yes, you will need the AD agent to run Identity Firewall.

You could also use Cut-Through Proxy for HTTP/HTTPS traffic and using LDAP for the authentication part.

That should do it bud.

Rate all of the helpful posts!!!

Regards,

Jcarvaja

Follow me on http://laguiadelnetworking.com

Looking for some Networking Assistance? Contact me directly at jcarvaja@laguiadelnetworking.com I will fix your problem ASAP. Cheers, Julio Carvajal Segura http://laguiadelnetworking.com
114
Views
0
Helpful
1
Replies