<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA, ACS, RSA / SecureID configuration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-acs-rsa-secureid-configuration/m-p/1544224#M267268</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They would only get the RSA prompt for token, on ACS 4.2 you can use RSA with an LDAP group mapping to achieve RSA authentication but still pass the desired DAL based on their LDAP mapping.&amp;nbsp; The username in RSA would have to be the same as the username in LDAP for this to work.&lt;/P&gt;&lt;P&gt;--Jesse&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Nov 2010 20:35:00 GMT</pubDate>
    <dc:creator>jedubois</dc:creator>
    <dc:date>2010-11-18T20:35:00Z</dc:date>
    <item>
      <title>ASA, ACS, RSA / SecureID configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-acs-rsa-secureid-configuration/m-p/1544223#M267263</link>
      <description>&lt;P&gt;I know this has been asked in a few different ways but I need to clarify the user experience under the following configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ASA uses ACS4.2 as a radius server and it also provides downloaded ACLs depending on the users group within LDAP&lt;/P&gt;&lt;P&gt;Our Security department would like to implement two factor using RSA. The desired result would be to maintain the functionality of ACS and the Downloadable ACLs but use RSA secureID as another authentication source. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am unclear of is what the user experience would be. If I was to setup Secureid / RSA server as an external Database within ACS and ASA using ACS as the Radius server.&amp;nbsp; When the client views the anyconnect window will they put LDAP username and password in click connect and then wait for some other challenge?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently using ASA 8.3&lt;/P&gt;&lt;P&gt;Anyconnect 2.5.017&lt;/P&gt;&lt;P&gt;ACS 4.2&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:27:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-acs-rsa-secureid-configuration/m-p/1544223#M267263</guid>
      <dc:creator>adrianoden</dc:creator>
      <dc:date>2019-03-26T00:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA, ACS, RSA / SecureID configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-acs-rsa-secureid-configuration/m-p/1544224#M267268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They would only get the RSA prompt for token, on ACS 4.2 you can use RSA with an LDAP group mapping to achieve RSA authentication but still pass the desired DAL based on their LDAP mapping.&amp;nbsp; The username in RSA would have to be the same as the username in LDAP for this to work.&lt;/P&gt;&lt;P&gt;--Jesse&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Nov 2010 20:35:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-acs-rsa-secureid-configuration/m-p/1544224#M267268</guid>
      <dc:creator>jedubois</dc:creator>
      <dc:date>2010-11-18T20:35:00Z</dc:date>
    </item>
  </channel>
</rss>

