Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Can I use Radius to get AD group info

I am using LDAP on my ASA and DAP, to assign VPN users from different AD group with different network access.  But now my LDAP server is about to be decommissioned, and I only can get a Radius server in replacment.  So, can I use Radius like I used LDAP 'memberOf' attribute to give my VPN users different access based on their WINs AD group?

Thanks a lot.

  • VPN
Cisco Employee

Can I use Radius to get AD group info

RADIUS will rely on class attribute to pick a gorup policy.

Supported RADIUS attributes on ASA:

The mechanics within to map groups to anything on AD is not something I'm aware.

Incidentally it's first time I hear about AD without possibility to use LDAP (or LDAPS).

This widget could not be displayed.