Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

ASA VPN and NAC using Cisco Clean Access

I currently have ASA VPN that is cofigured to work with NAC inline mode with Virtual GW and CCA using Single Sign On and Active Directory via a MS IAS server. Everything works fine. We want to have vendors use this solution as well but do not want to give them AD accounts. We would like the Vendor to connect to VPN but since there is no AD account they must authentcate to teh NAC local database but this is not working. We want to move away from users have local ASA VPN accounts to using the VPN through the ASA but using SSO and the NAC. Can this be done without creating Active Directory Accounts for the Vendors?

6 REPLIES
Silver

Re: ASA VPN and NAC using Cisco Clean Access

You can configure Cisco NAC Appliance to automatically authenticate Clean Access Agent users who are already logged into a Windows domain. AD SSO allows users logging into AD on their Windows systems to automatically go through posture assessment/Clean Access certification without ever having to login through the Agent. Cisco NAC Appliance supports Windows Single Sign-On (SSO) on Windows Vista/XP/2000 client machines and AD on Windows 2000/2003 servers.

http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/411/cas411/s_adsso.html#wp1148380

New Member

Re: ASA VPN and NAC using Cisco Clean Access

Thanks for the reply but that is not my issue ...please see above comments. I ahve that solution in place and working fine. My question is can I provide VPN access to a vendor WITHOUT giving them a AD account or giving them a local account on the ASA. I wanted to know if it is possible for them to use VPN and authenticate to the NAC server local database but I was told by a Cisco VPN ENG and NAC ENG it can be done but the vondor would use no authentication to the VPN tunnel group and passed to the NAC inside...security HOLE...which defeats the purpose of the VPN session to our Network. So I will just give the vendors an AD account and have them use SSO as well.

Thanks

Re: ASA VPN and NAC using Cisco Clean Access

VPN SSO requires a Radius Accounting packet to reach the NAC Sserver from the ASA. If you do not want to use AD or local ASA, you will need to set up another authentication server and associated to a group used by the vendors.

-Dan Laden

New Member

Re: ASA VPN and NAC using Cisco Clean Access

thanks

New Member

Re: ASA VPN and NAC using Cisco Clean Access

I have an update. My configuration is the same. I am trying to use the mapping feature on the NAC manager. The vendor will have an AD account and be in the VPNUsers AD group but I am trying to assign different NAC roles depending on the user in that group. I read the docs but I am no MS IAS expert and I have tried a couple attributes but not working. Getting the mapping rules working would really fix all the issues because I can assign more restrictive roles to vendors and create roles for IT...Finance ETC but maintain 1 RADIUS server...with 1 AD group....I can find example using LDAP mapping but nothing of real help for Radius mapping

New Member

Re: ASA VPN and NAC using Cisco Clean Access

I am using VPN SSO ...I dont have AD SSO configured ...can I have both??

310
Views
0
Helpful
6
Replies