Cisco ASA Series Cli Configuration Manual page 865

Software version 9.0 for the services module
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

Chapter 1
Configuring AAA Servers and the Local Database
To set up VPN user authorization using LDAP, perform the following steps.
Detailed Steps
Command
Step 1
aaa-server server_group protocol {kerberos | ldap |
nt | radius | sdi | tacacs+}
Example:
hostname(config)# aaa-server servergroup1 protocol
ldap
hostname(config-aaa-server-group)
Step 2
tunnel-group groupname
Example:
hostname(config)# tunnel-group remotegrp
Step 3
tunnel-group groupname general-attributes
Example:
hostname(config)# tunnel-group remotegrp
general-attributes
Step 4
authorization-server-group group-tag
Example:
hostname(config-general)# authorization-server-group
ldap_dir_1
Examples
While there are other authorization-related commands and options available for specific requirements,
the following example shows commands for enabling user authorization with LDAP. The example then
creates an IPsec remote access tunnel group named remote-1, and assigns that new tunnel group to the
previously created ldap_dir_1 AAA server group for authorization:
hostname(config)# tunnel-group remote-1 type ipsec-ra
hostname(config)# tunnel-group remote-1 general-attributes
hostname(config-general)# authorization-server-group ldap_dir_1
hostname(config-general)#
After you complete this configuration work, you can then configure additional LDAP authorization
parameters such as a directory password, a starting point for searching a directory, and the scope of a
directory search by entering the following commands:
hostname(config)# aaa-server ldap_dir_1 protocol ldap
hostname(config-aaa-server-group)# aaa-server ldap_dir_1 host 10.1.1.4
hostname(config-aaa-server-host)# ldap-login-dn obscurepassword
hostname(config-aaa-server-host)# ldap-base-dn starthere
hostname(config-aaa-server-host)# ldap-scope subtree
hostname(config-aaa-server-host)#
Purpose
Creates a AAA server group.
Creates an IPsec remote access tunnel group named
remotegrp.
Associates the server group and the tunnel group.
Assigns a new tunnel group to a previously created
AAA server group for authorization.
Cisco ASA Series CLI Configuration Guide
Configuring AAA
1-19

Advertisement

Table of Contents
loading

Table of Contents