Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ASA DAP LDAP Inheritance ?

Is there any way, maybe through LUA script to check for membership in nested groups?

IE a user is directly a memeber of "Location Employees"

"Location Employees" is a memeber of  "Company Employees"

Making the rule allow anyone that is a member of "Company Employees" pass?

At the moment I can get around some of this by using LUA to match on groups ENDING in Employees but I have other cases that would work better. The only alternative I see is to create a bunch of new groups and make the users direct memebers.

1 REPLY

Re: ASA DAP LDAP Inheritance ?

Hi, there is a feature request for this, currently it is not supported

CSCso24147 VPN RA Active Directory/LDAP  Nested-Groups Support

hth

ivan

467
Views
0
Helpful
1
Replies