networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 4 posts ] 
Author Message
PostPosted: Mon Dec 19, 2011 2:39 pm 
Offline
Junior Member
Junior Member

Joined: Wed Jan 27, 2010 2:37 pm
Posts: 59
Certs: CCNA
Hello,

Is it possible to use both RSA SecureID for Authentication and Windows 2008 LDAP as Authorization? Basically what I currently have now is RSA as a radius for authentication. But I would also like to use Dynamic Access Policy ACL based on their Active directory group Membership. Is that possible?

Thanks,
Mike


Top
 Profile  
 
PostPosted: Mon Dec 19, 2011 3:00 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Nov 13, 2009 5:15 pm
Posts: 2050
Location: Pittsburgh
Certs: CCIE R&S,CCIP,JNCIA,VCP510
yes it is, I used it within asa for vpn authentication to put certain users within different tunnel groups depending on their ad names. It was setup for local as well. If you are used to cli, you are going to have to accomplish this within the asdm. There are some documents out there on how to setup dynamic acl's.

_________________
"I will prepare and some day my chance will come." - Abraham Lincoln
http://danielhertzberg.wordpress.com - I blog about networks!


Top
 Profile  
 
PostPosted: Wed Dec 21, 2011 2:17 pm 
Offline
Cisco Inferno
Cisco Inferno
User avatar

Joined: Mon Jul 10, 2006 12:58 am
Posts: 10202
Location: Seattle
Should be possible, although I've never used that exact combination. My setup doesn't require fundamental differences between AD groups for VPN access, so I'm able to run them all within the same tunnel-group, but I use DAP in conjunction with AD and it works great.

_________________
Reasonably un-nerdy blog:
americanwerewolfinbelgrade.wordpress.com/


Top
 Profile  
 
PostPosted: Fri Feb 17, 2012 8:17 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Sat Oct 20, 2007 11:05 am
Posts: 1953
Location: Plano, TX
Certs: CCNA
I just searched this yesterday looking for the same answer. There is almost no documentation on this specific setup but there is a Cisco document "Kerberos Authentication and LDAP Authorization Server Groups". Link Only in our case SDI is for authentication and ldap for authorization.

Simply setup an aaa-server group for the rsa like you normally would for authentication. Then setup an aaa-server group for ldap the same way as if you are using it for authentication and add the appropriate ldap attribute maps to associate the ldap memberOf (AD groups) with group policy.

Then on your tunnel group select the rsa aaa-server group for authentication. Go to the authorization section and select the ldap aaa-server group for authorization.

That's it.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 17 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group