Cisco ASA 5505 Configuration Manual page 1735

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Appendix B
Configuring an External Server for Authorization and Authentication
Figure B-1
Configuring an External LDAP Server
The VPN 3000 Concentrator and the ASA/PIX 7.0 required a Cisco LDAP schema for authorization
operations. Beginning with Version 7.1.x, the adaptive security appliance performs authentication and
authorization, using the native LDAP schema, and the Cisco schema is no longer needed.
You configure authorization (permission policy) using an LDAP attribute map. For examples, see
Active Directory/LDAP VPN Remote Access Authorization Use Cases, page
This section describes the structure, schema, and attributes of an LDAP server. It includes the following
topics:
The specific steps of these processes vary, depending on which type of LDAP server you are using.
For more information on the LDAP protocol, see RFCs 1777, 2251, and 2849.
Note
Organizing the Security Appliance for LDAP Operations
This section describes how to perform searches within the LDAP hierarchy and authenticated binding to
the LDAP server on the adaptive security appliance. It includes the following topics:
OL-20339-01
Policy Enforcement Flow
Organizing the Security Appliance for LDAP Operations, page B-3
Defining the Security Appliance LDAP Configuration, page B-6
Active Directory/LDAP VPN Remote Access Authorization Use Cases, page B-16
Searching the Hierarchy, page B-4
Binding the Security Appliance to the LDAP Server, page B-5
Login DN Example for Active Directory, page B-5
Configuring an External LDAP Server
Cisco ASA 5500 Series Configuration Guide using ASDM
B-16.
B-3

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents