<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA+AD+Authorization in VPN</title>
    <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464133#M36070</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The first article is the one that I have been following and does not work.&amp;nbsp; It has been noted many, many times in these forums.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second article covers dial-in access allow or permit which is not quite what we need.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Jun 2010 10:18:06 GMT</pubDate>
    <dc:creator>charlesdf22</dc:creator>
    <dc:date>2010-06-22T10:18:06Z</dc:date>
    <item>
      <title>ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464131#M36068</link>
      <description>&lt;P&gt;Has anyone managed to get the ASA (8.2) working with LDAP/ AD to perform authorization/ group mapping's based on AD group membership?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found numerous postings on these forums, but not anyone who has managed to get it working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have several groups where we are using the drop down selector and would like to leverage AD groups for access.&amp;nbsp; If the user is a member of the group, then they can sign in.&amp;nbsp; If not, they get denied access.&amp;nbsp; It sounds pretty straight forward, but it doesn't seem to work like it is supposed to.&amp;nbsp; Our user community pretty much will only use AnyConnect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2010 09:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464131#M36068</guid>
      <dc:creator>charlesdf22</dc:creator>
      <dc:date>2010-06-22T09:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464132#M36069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you checked the following sample configuration:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808d1a7c.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808d1a7c.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008089149d.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008089149d.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen it working based on the above sample configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 10:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464132#M36069</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-22T10:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464133#M36070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The first article is the one that I have been following and does not work.&amp;nbsp; It has been noted many, many times in these forums.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second article covers dial-in access allow or permit which is not quite what we need.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 10:18:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464133#M36070</guid>
      <dc:creator>charlesdf22</dc:creator>
      <dc:date>2010-06-22T10:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464134#M36071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Actually.... it turns out we may have found a potential fix here... &lt;/SPAN&gt;&lt;A class="jive-link-message-small" href="https://community.cisco.com/message/850498#850498"&gt;https://supportforums.cisco.com/message/850498#850498&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The documentation refers to Radius-Class, which doesn't seem to accomplish anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like Tunnel-Group-Lock is the key.&amp;nbsp; However, it's denying everything right now, which I guess it better than what it was doing before.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 10:26:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464134#M36071</guid>
      <dc:creator>charlesdf22</dc:creator>
      <dc:date>2010-06-22T10:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464135#M36072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The map name would be "map-name&amp;nbsp; memberOf IETF-Radius-Class".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please run "debug ldap 255" and try to authenticate with the user, and it will show you the full path of the CN memberOf for that user, and on the actual LDAP mapping, you would need to include that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 10:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464135#M36072</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-22T10:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464136#M36073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have that, just like the doc says and it still does not work correctly.&amp;nbsp; The issue is that it sees the group mapping, verifies it and then lets the user in with another group.&amp;nbsp; It seems the authorization is busted and doesn't really do anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just like here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-message-small" href="https://community.cisco.com/message/1010142#1010142"&gt;https://supportforums.cisco.com/message/1010142#1010142&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kind of here: &lt;/SPAN&gt;&lt;A class="jive-link-message-small" href="https://community.cisco.com/message/3021960#3021960"&gt;https://supportforums.cisco.com/message/3021960#3021960&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It looks like they never got it working here:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-message-small" href="https://community.cisco.com/message/3059302#3059302"&gt;https://supportforums.cisco.com/message/3059302#3059302&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any idea what the Tunnel lock stuff does?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 11:38:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464136#M36073</guid>
      <dc:creator>charlesdf22</dc:creator>
      <dc:date>2010-06-22T11:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464137#M36074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Don't worry about tunnel group lock, it is not what you are after.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please share your configuration, and also advise which group-policy is the user supposed to be connected in, and which group-policy does the user actually get connected to ("show vpn-sessiondb svc filter name &lt;USERNAME&gt;" output will show which group-policy the user is actually dropped in after the ldap attribute mapping). Thanks.&lt;/USERNAME&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 11:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464137#M36074</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-22T11:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464138#M36075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ldap attribute-map ad-members&lt;/P&gt;&lt;P&gt;&amp;nbsp; map-name&amp;nbsp; memberOf IETF-Radius-Class&lt;/P&gt;&lt;P&gt;&amp;nbsp; map-value memberOf "CN=NS-ILO-Admins,OU=Groups,OU=Network Services,OU=X,OU=Depts,DC=X,DC=company,DC=com" eng-test&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Here is the debug for the groups:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;[258] &lt;SPAN&gt; &lt;/SPAN&gt;memberOf: value = CN=NS-OU-Admins,OU=Groups,OU=Network Services,OU=X,OU=Depts,DC=X,DC=company,DC=&lt;/DIV&gt;&lt;DIV&gt;[258] &lt;SPAN&gt; &lt;/SPAN&gt;mapped to IETF-Radius-Class: value = CN=NS-OU-Admins,OU=Groups,OU=Network Services,OU=X,OU=Depts,DC=X,DC=company,DC=com&lt;/DIV&gt;&lt;DIV&gt;[258] &lt;SPAN&gt; &lt;/SPAN&gt;mapped to LDAP-Class: value = CN=NS-OU-Admins,OU=Groups,OU=Network Services,OU=X,OU=Depts,DC=X,DC=company,DC=com&lt;/DIV&gt;&lt;DIV&gt;[258] &lt;SPAN&gt; &lt;/SPAN&gt;memberOf: value = CN=ACS-Server-Admins,OU=ACS,OU=Network Services,OU=X,OU=Depts,DC=X,DC=company,D&lt;/DIV&gt;&lt;DIV&gt;[258] &lt;SPAN&gt; &lt;/SPAN&gt;mapped to IETF-Radius-Class: value = CN=ACS-Server-Admins,OU=ACS,OU=Network Services,OU=X,OU=Depts,DC=X,DC=company,DC=com&lt;/DIV&gt;&lt;DIV&gt;[258] &lt;SPAN&gt; &lt;/SPAN&gt;mapped to LDAP-Class: value = CN=ACS-Server-Admins,OU=ACS,OU=Network Services,OU=X,OU=Depts,DC=X,DC=company,DC=com&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;[258] &lt;SPAN&gt; &lt;/SPAN&gt;memberOf: value = CN=X-TS-Users,OU=Groups,OU=Testing,OU=X,OU=Depts,DC=X,DC=company,DC=com&lt;/DIV&gt;&lt;DIV&gt;[258] &lt;SPAN&gt; &lt;/SPAN&gt;mapped to IETF-Radius-Class: value = CN=X-TS-Users,OU=Groups,OU=Testing,OU=X,OU=Depts,DC=X,DC=company,DC=com&lt;/DIV&gt;&lt;DIV&gt;[258] &lt;SPAN&gt; &lt;/SPAN&gt;mapped to LDAP-Class: value = CN=X-TS-Users,OU=Groups,OU=Testing,OU=X,OU=Depts,DC=X,DC=company,DC=com&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;Session Type: IPsec&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Username&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : USERNAME&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Index&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 16&lt;/DIV&gt;&lt;DIV&gt;ATestinggned IP&amp;nbsp; : 10.180.128.11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Public IP&amp;nbsp;&amp;nbsp;&amp;nbsp; : X.X.X.X&lt;/DIV&gt;&lt;DIV&gt;Protocol&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : IKE IPsec&lt;/DIV&gt;&lt;DIV&gt;License&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : IPsec&lt;/DIV&gt;&lt;DIV&gt;Encryption&amp;nbsp;&amp;nbsp; : AES128&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hashing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : SHA1&lt;/DIV&gt;&lt;DIV&gt;Bytes Tx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1970&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bytes Rx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1698&lt;/DIV&gt;&lt;DIV&gt;Group Policy : CN=X-TS-Users,OU=Groups,OU=Testing,OU=X,OU=Depts,DC=X,DC=company,DC=com&lt;/DIV&gt;&lt;DIV&gt;Tunnel Group : eng-test&lt;/DIV&gt;&lt;DIV&gt;Login Time&amp;nbsp;&amp;nbsp; : 08:09:19 EDT Tue Jun 22 2010&lt;/DIV&gt;&lt;DIV&gt;Duration&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0h:02m:09s&lt;/DIV&gt;&lt;DIV&gt;Inactivity&amp;nbsp;&amp;nbsp; : 0h:00m:00s&lt;/DIV&gt;&lt;DIV&gt;NAC Result&amp;nbsp;&amp;nbsp; : Unknown&lt;/DIV&gt;&lt;DIV&gt;VLAN Mapping : Static&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VLAN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3036&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;As you can see, it's just picking whatever group it feels like and not the correct one.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 12:15:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464138#M36075</guid>
      <dc:creator>charlesdf22</dc:creator>
      <dc:date>2010-06-22T12:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464139#M36076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The map-value that you have configured is for the following:&lt;/P&gt;&lt;P&gt;map-value memberOf "&lt;STRONG&gt;CN=NS-ILO-Admins,&lt;/STRONG&gt;OU=Groups,OU=Network Services,OU=X,OU=Depts,DC=X,DC=company,DC=com" eng-test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, base on the debug, the user is not a member of the above configured map value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you change the map-value to the following for example:&lt;/P&gt;&lt;P&gt;map-value memberOf "&lt;STRONG&gt;CN=NS-OU-Admins&lt;/STRONG&gt;,OU=Groups,OU=Network Services,OU=X,OU=Depts,DC=X,DC=company,DC=com" eng-test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, that particular user will be put into the correct group-policy (name: eng-test), assuming you have configured group-policy with "eng-test" as its name.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 12:23:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464139#M36076</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-22T12:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464140#M36077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is correct.&amp;nbsp; Even though the user is not a member of that group, they are ending up in that group-policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 12:43:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464140#M36077</guid>
      <dc:creator>charlesdf22</dc:creator>
      <dc:date>2010-06-22T12:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464141#M36078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I don't think I understand it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are 2 different configuration policies:&lt;/P&gt;&lt;P&gt;1) tunnel-group&lt;/P&gt;&lt;P&gt;2) group-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"eng-test" configured I believe is the tunnel-group. Do you also have group-policy named "eng-test" as well? ie: having both tunnel-group and group-policy with the name "eng-test"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the "show vpn-sessiondb svc" output provided earlier, the user is connected to the following:&lt;/P&gt;&lt;P&gt;Group Policy : CN=X-TS-Users,OU=Groups,OU=Testing,OU=X,OU=Depts,DC=X,DC=company,DC=com&lt;BR /&gt;Tunnel Group : eng-test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the group-policy assigned is "CN=X-TS-Users,OU=Groups,OU=Testing,OU=X,OU=Depts,DC=X,DC=company,DC=com" which is just a false group-policy as I don't think you have group-policy with name "CN=X-TS-Users,OU=Groups,OU=Testing,OU=X,OU=Depts,DC=X,DC=company,DC=com" configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The mapping is done on group-policy, not on tunnel-group. You can configure 1 tunnel-group where all the users are connected to, however, having different users being mapped to different group-policy (where all the specific policies are configured).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share the following output to understand what is actually configured:&lt;/P&gt;&lt;P&gt;show run tunnel-group&lt;/P&gt;&lt;P&gt;show run group-policy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 12:50:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464141#M36078</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-22T12:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464142#M36079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group eng-test type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group eng-test general-attributes&lt;/P&gt;&lt;P&gt; address-pool eng-test&lt;/P&gt;&lt;P&gt; authentication-server-group Win-Domain&lt;/P&gt;&lt;P&gt; default-group-policy eng-test&lt;/P&gt;&lt;P&gt;tunnel-group eng-test webvpn-attributes&lt;/P&gt;&lt;P&gt; group-alias Engineering-testing enable&lt;/P&gt;&lt;P&gt;tunnel-group eng-test ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *****&lt;/P&gt;&lt;P&gt;tunnel-group wireless type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group wireless general-attributes&lt;/P&gt;&lt;P&gt; address-pool wireless&lt;/P&gt;&lt;P&gt; authentication-server-group Win-Domain&lt;/P&gt;&lt;P&gt; default-group-policy wireless&lt;/P&gt;&lt;P&gt;tunnel-group wireless webvpn-attributes&lt;/P&gt;&lt;P&gt; group-alias Wireless enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy DfltGrpPolicy attributes&lt;/P&gt;&lt;P&gt; banner value Testing&lt;/P&gt;&lt;P&gt; vpn-idle-timeout 90&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec svc webvpn&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value Standard-Split&lt;/P&gt;&lt;P&gt; nem enable&lt;/P&gt;&lt;P&gt;group-policy eng-test internal&lt;/P&gt;&lt;P&gt;group-policy eng-test attributes&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec svc webvpn&lt;/P&gt;&lt;P&gt; vlan 3036&lt;/P&gt;&lt;P&gt; address-pools none&lt;/P&gt;&lt;P&gt; ipv6-address-pools none&lt;/P&gt;&lt;P&gt; webvpn&lt;/P&gt;&lt;P&gt;&amp;nbsp; svc ask enable&lt;/P&gt;&lt;P&gt;group-policy wireless internal&lt;/P&gt;&lt;P&gt;group-policy wireless attributes&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec svc webvpn&lt;/P&gt;&lt;P&gt; vlan 3011&lt;/P&gt;&lt;P&gt; address-pools none&lt;/P&gt;&lt;P&gt; ipv6-address-pools none&lt;/P&gt;&lt;P&gt; webvpn&lt;/P&gt;&lt;P&gt;&amp;nbsp; svc ask enable&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 14:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464142#M36079</guid>
      <dc:creator>charlesdf22</dc:creator>
      <dc:date>2010-06-22T14:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464143#M36080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is the same exact issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-thread-small" href="https://community.cisco.com/thread/2010078"&gt;https://supportforums.cisco.com/thread/2010078&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, I will have up to 20 different groups that a user can select.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, engineering, sales, administration, management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some users will need to access different groups based upon their needs.&amp;nbsp; Someone from engineering will need to select the drop down (or url) to access the management group so they can make switch changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My basic need is that the system has to check an LDAP group, determine memberOf and allow access.&amp;nbsp; This sounds like basic authorization, is it not?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 14:40:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464143#M36080</guid>
      <dc:creator>charlesdf22</dc:creator>
      <dc:date>2010-06-22T14:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA+AD+Authorization</title>
      <link>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464144#M36081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is absolutely&amp;nbsp; basic authorization, however, the ldap mapping has been configured incorrectly.&lt;/P&gt;&lt;P&gt;You would need to map the correct ldap path of that user to a group-policy as advised earlier.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 12:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/asa-ad-authorization/m-p/1464144#M36081</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-23T12:46:52Z</dc:date>
    </item>
  </channel>
</rss>

