<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP group with multiple servers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ldap-group-with-multiple-servers/m-p/2907577#M36260</link>
    <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have an ASA using a AAA LDAP server group for SSH login. In the AAA LDAP server group there are two servers, each communicating with a different domain.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If I have server1 identified first in the list, a login on that server's domain (domain1) is successful.&lt;/P&gt;
&lt;P&gt;If i have server2 identified first, a login on that server's domain (domain2) is successful.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If I have server1 identified first, a login on domain2 is not successful even though server2 is listed just after server1 in the group. Same thing happens if I try to use a domain1 account if server2 is listed first.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If server1 is offline and listed as primary then I can login with credentials on domain2 but not if server1 is online.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is there a way to have the ASA check server2 if authentication with server1 fails? &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:45:35 GMT</pubDate>
    <dc:creator>jslusher11</dc:creator>
    <dc:date>2019-03-11T06:45:35Z</dc:date>
    <item>
      <title>LDAP group with multiple servers</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-group-with-multiple-servers/m-p/2907577#M36260</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have an ASA using a AAA LDAP server group for SSH login. In the AAA LDAP server group there are two servers, each communicating with a different domain.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If I have server1 identified first in the list, a login on that server's domain (domain1) is successful.&lt;/P&gt;
&lt;P&gt;If i have server2 identified first, a login on that server's domain (domain2) is successful.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If I have server1 identified first, a login on domain2 is not successful even though server2 is listed just after server1 in the group. Same thing happens if I try to use a domain1 account if server2 is listed first.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If server1 is offline and listed as primary then I can login with credentials on domain2 but not if server1 is online.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is there a way to have the ASA check server2 if authentication with server1 fails? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-group-with-multiple-servers/m-p/2907577#M36260</guid>
      <dc:creator>jslusher11</dc:creator>
      <dc:date>2019-03-11T06:45:35Z</dc:date>
    </item>
    <item>
      <title>You need a radius server to</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-group-with-multiple-servers/m-p/2907578#M36261</link>
      <description>&lt;P&gt;You need a radius server to help you do this, most radius servers can search the AD and if the user doesn't actually exist in the first AD, it will continue to the next. The ASA can't do this on it's own, as the first server is still online, and sends a reject when the user is not found, which the ASA interprets as "that user should not get access", which is why it works, when the first server is offline, which is interpreted by the asa as aaa server down, move on to next server.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 15:44:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-group-with-multiple-servers/m-p/2907578#M36261</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-05-12T15:44:43Z</dc:date>
    </item>
    <item>
      <title>Makes sense. Thanks for the</title>
      <link>https://community.cisco.com/t5/network-access-control/ldap-group-with-multiple-servers/m-p/2907579#M36263</link>
      <description>&lt;P&gt;Makes sense. Thanks for the help. I wasn't sure if I was doing something wrong or just uncertain on how it all works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 17:22:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ldap-group-with-multiple-servers/m-p/2907579#M36263</guid>
      <dc:creator>jslusher11</dc:creator>
      <dc:date>2016-05-12T17:22:03Z</dc:date>
    </item>
  </channel>
</rss>

