<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA and Active Directory authorization issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-and-active-directory-authorization-issue/m-p/3303305#M550800</link>
    <description>&lt;P&gt;Unfortunately the ASA only knows what the AD servers tells it. Until there’s a new login event it won’t know the user has changed addresses in moving from wired to wireless.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If if you had something like Cisco ISE it could authorize both wired and wireless users as they move around.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Dec 2017 11:15:23 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-12-28T11:15:23Z</dc:date>
    <item>
      <title>ASA and Active Directory authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-and-active-directory-authorization-issue/m-p/3302718#M550797</link>
      <description>&lt;P&gt;Hello, everybody,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have an office where ASA 5508 on the edge and users are allowed to browse Internet after they've logged with their AD credentials. Everything works fine, except one thing:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some users work with laptops connected to wired network. Sometimes they attend meetings where they have to use Wifi connection. After they change wired connection to wireless, ASA restrict them Internet access.&amp;nbsp; It happens until "account logon" event in AD occurs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How could I manually initiate accout logon or configure ASA to allow a user to use wired and wireless network? I mean, without a long period of time to wait...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is my AAA configuration:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;aaa-server LDAP protocol ldap&lt;BR /&gt;aaa-server LDAP (inside) host 10.39.1.11&lt;BR /&gt; ldap-base-dn DC=blablabla,DC=ru&lt;BR /&gt; ldap-scope subtree&lt;BR /&gt; ldap-naming-attribute sAMAccountName&lt;BR /&gt; ldap-login-password *****&lt;BR /&gt; ldap-login-dn CN=RU-SCCMNetAccess,OU=IT,OU=.RU,DC=blablabla,DC=ru&lt;BR /&gt; server-type microsoft&lt;BR /&gt; ldap-attribute-map ANYCONNECT-LOGIN&lt;BR /&gt;aaa-server Duo-LDAP protocol ldap&lt;BR /&gt;aaa-server Duo-LDAP (outside) host &lt;BR /&gt; timeout 60&lt;BR /&gt; server-port 636&lt;BR /&gt; ldap-base-dn dc=&lt;BR /&gt; ldap-naming-attribute cn&lt;BR /&gt; ldap-login-password *****&lt;BR /&gt; ldap-login-dn dc=&lt;BR /&gt; ldap-over-ssl enable&lt;BR /&gt; server-type auto-detect&lt;BR /&gt;user-identity default-domain LOCAL&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I could provide any information required.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks in advance,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ilya&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:42:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-and-active-directory-authorization-issue/m-p/3302718#M550797</guid>
      <dc:creator>Ilya Semenov</dc:creator>
      <dc:date>2020-02-21T18:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA and Active Directory authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-and-active-directory-authorization-issue/m-p/3303305#M550800</link>
      <description>&lt;P&gt;Unfortunately the ASA only knows what the AD servers tells it. Until there’s a new login event it won’t know the user has changed addresses in moving from wired to wireless.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If if you had something like Cisco ISE it could authorize both wired and wireless users as they move around.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 11:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-and-active-directory-authorization-issue/m-p/3303305#M550800</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-12-28T11:15:23Z</dc:date>
    </item>
  </channel>
</rss>

