Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Can I use Radius to get AD group info

I am using LDAP on my ASA and DAP, to assign VPN users from different AD group with different network access.  But now my LDAP server is about to be decommissioned, and I only can get a Radius server in replacment.  So, can I use Radius like I used LDAP 'memberOf' attribute to give my VPN users different access based on their WINs AD group?

Thanks a lot.

  • VPN
1 REPLY
Cisco Employee

Can I use Radius to get AD group info

RADIUS will rely on class attribute to pick a gorup policy.

Supported RADIUS attributes on ASA:

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ref_extserver.html

The mechanics within to map groups to anything on AD is not something I'm aware.

Incidentally it's first time I hear about AD without possibility to use LDAP (or LDAPS).

189
Views
0
Helpful
1
Replies
This widget could not be displayed.