<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP memberOf maps OK first login attempt, but not on later ones in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ldap-memberof-maps-ok-first-login-attempt-but-not-on-later-ones/m-p/2034749#M163610</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I neglected to mention that the configuration in question is on an ASA 5520 active/standby pair, running 8.2.1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Sep 2012 18:57:52 GMT</pubDate>
    <dc:creator>desmith</dc:creator>
    <dc:date>2012-09-27T18:57:52Z</dc:date>
    <item>
      <title>LDAP memberOf maps OK first login attempt, but not on later ones</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-memberof-maps-ok-first-login-attempt-but-not-on-later-ones/m-p/2034748#M163574</link>
      <description>&lt;P&gt;Hello!&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm seeing a very weird problem:&amp;nbsp; I'm trying to use LDAP memberOf values to map users at login into different ASA groups, with different policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This mapping works on the first login, but not thereafter (until/unless a break of many hours occurs, and then it works on the first login *again*).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Excerpt from "debug ldap 255":&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First attempt:&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 10.0px Arial;"&gt;[11258]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; memberOf: value = CN=Split-tunnel,CN=Users,DC=ldproducts,DC=local&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 10.0px Arial;"&gt;[11258]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mapped to IETF-Radius-Class: value = Split-Tunnel-Group&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 10.0px Arial;"&gt;[11258]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; uSNChanged: value = 6995298&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second, third, etc. attempts:&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 10.0px Arial;"&gt;[11261]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; memberOf: value = CN=Split-tunnel,CN=Users,DC=ldproducts,DC=local&lt;/P&gt;&lt;P style="margin: 0.0px 0.0px 0.0px 0.0px; font: 10.0px Arial;"&gt;[11261]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; uSNChanged: value = 7127750&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hmmm...very odd.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions would be greatly appreciated!&lt;/P&gt;&lt;P&gt;Deb&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:36:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-memberof-maps-ok-first-login-attempt-but-not-on-later-ones/m-p/2034748#M163574</guid>
      <dc:creator>desmith</dc:creator>
      <dc:date>2019-03-11T02:36:18Z</dc:date>
    </item>
    <item>
      <title>LDAP memberOf maps OK first login attempt, but not on later ones</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-memberof-maps-ok-first-login-attempt-but-not-on-later-ones/m-p/2034749#M163610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I neglected to mention that the configuration in question is on an ASA 5520 active/standby pair, running 8.2.1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2012 18:57:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-memberof-maps-ok-first-login-attempt-but-not-on-later-ones/m-p/2034749#M163610</guid>
      <dc:creator>desmith</dc:creator>
      <dc:date>2012-09-27T18:57:52Z</dc:date>
    </item>
    <item>
      <title>LDAP memberOf maps OK first login attempt, but not on later ones</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-memberof-maps-ok-first-login-attempt-but-not-on-later-ones/m-p/2034750#M163629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am certainly not Cisco expert, but from a LDAP perspective, I do not think the memberOf attribute will be reliable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;memberOf is an operationanal, (ie not user updatable), server side set recirpical value of the member Attribute from the group entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So when a user is added to a group which by adding the DN of the user to the Group's Member attribute, the USN of the Group changes.&lt;/P&gt;&lt;P&gt;However, the USN of the user does NOT change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addtion, no nested group entries would ever be represented within the memberOf attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To accurateley determine which groups the user is a member of you should use a query for all groups similer to:&lt;/P&gt;&lt;PRE style="margin: 1em 36px 1em 36.41666793823242px; padding: 0.5em; border: 1px solid #dddddd; outline: none; font-family: Monaco, 'Courier New', Courier, monospace; overflow: auto; clear: both; background-color: #f9f9f9; color: #000000;"&gt;(member:1.2.840.113556.1.4.1941:=(CN=John Smith,DC=MyDomain,DC=NET))&lt;/PRE&gt;&lt;P&gt;-jim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Sep 2012 09:00:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-memberof-maps-ok-first-login-attempt-but-not-on-later-ones/m-p/2034750#M163629</guid>
      <dc:creator>jim</dc:creator>
      <dc:date>2012-09-30T09:00:43Z</dc:date>
    </item>
  </channel>
</rss>

