<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: integrate VPN with AD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4607339#M1089929</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/730730"&gt;@mautez_mah&lt;/a&gt; the screenshot is of the LDAP attribute map, which won't be configured.&lt;/P&gt;
&lt;P&gt;Please provide your configuration for review, so we can determine what you have configured.&lt;/P&gt;</description>
    <pubDate>Tue, 10 May 2022 09:49:30 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-05-10T09:49:30Z</dc:date>
    <item>
      <title>integrate VPN with AD</title>
      <link>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4606692#M1089889</link>
      <description>&lt;P&gt;Hi ,&amp;nbsp;&lt;BR /&gt;I am working in FW ASA ,&amp;nbsp;&lt;BR /&gt;SSL-VPN integrated with AD ,and all users created in AD within specific group&lt;BR /&gt;how can I add new group to AD and match it in ASA&amp;nbsp;&lt;BR /&gt;how can ASA know that group in ASA should got users from specific Group in AD&amp;nbsp;&lt;BR /&gt;ju&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 07:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4606692#M1089889</guid>
      <dc:creator>mautez_mah</dc:creator>
      <dc:date>2022-05-09T07:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: integrate VPN with AD</title>
      <link>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4606712#M1089890</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/730730"&gt;@mautez_mah&lt;/a&gt; &lt;/P&gt;
&lt;P&gt;If using LDAP, utilise an LDAP attribute map to map AD group.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2020/04/03/asa-remote-access-vpn-using-ldap/" target="_blank"&gt;https://integratingit.wordpress.com/2020/04/03/asa-remote-access-vpn-using-ldap/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 08:07:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4606712#M1089890</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-05-09T08:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: integrate VPN with AD</title>
      <link>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4606715#M1089891</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;many thanks , can I know how to do it thru ASDM please &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 08:16:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4606715#M1089891</guid>
      <dc:creator>mautez_mah</dc:creator>
      <dc:date>2022-05-09T08:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: integrate VPN with AD</title>
      <link>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4606719#M1089892</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/98634-asa-ldap-group-pol.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/98634-asa-ldap-group-pol.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.petenetlive.com/KB/Article/0001152" target="_blank"&gt;https://www.petenetlive.com/KB/Article/0001152&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 08:19:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4606719#M1089892</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-05-09T08:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: integrate VPN with AD</title>
      <link>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4606725#M1089894</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp; How are using the AD on this case? Are you using LDAP protocol on ASA or do you use ISE and then ISE integrates with AD?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Why does your vpn users can not&amp;nbsp; just be on the vpn user group?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 08:25:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4606725#M1089894</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-05-09T08:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: integrate VPN with AD</title>
      <link>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4607321#M1089927</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using AD not ISE , I just need to know how to match group in ASA with group in AD&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 09:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4607321#M1089927</guid>
      <dc:creator>mautez_mah</dc:creator>
      <dc:date>2022-05-10T09:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: integrate VPN with AD</title>
      <link>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4607323#M1089928</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I have attached screen-shots , I can't see configuration for LDAP or Access dynamic ,&lt;BR /&gt;even we are using AD for all VPN users , is this because FW is context&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 09:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4607323#M1089928</guid>
      <dc:creator>mautez_mah</dc:creator>
      <dc:date>2022-05-10T09:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: integrate VPN with AD</title>
      <link>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4607339#M1089929</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/730730"&gt;@mautez_mah&lt;/a&gt; the screenshot is of the LDAP attribute map, which won't be configured.&lt;/P&gt;
&lt;P&gt;Please provide your configuration for review, so we can determine what you have configured.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 09:49:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4607339#M1089929</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-05-10T09:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: integrate VPN with AD</title>
      <link>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4607355#M1089930</link>
      <description>&lt;P&gt;AD and ISE are completely different things. What I asked is if you are using ISE or searching the AD with LDAP directling from ASA&lt;/P&gt;&lt;P&gt;&amp;nbsp;then you need to follow this&amp;nbsp; instruction:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/91831-mappingsvctovpn.html" href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/91831-mappingsvctovpn.html" target="_self"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/91831-mappingsvctovpn.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then, I said that instead searching for group if dont make more sense add one group for VPN users and then look at this group only but if what work for you is search for a group on AD using LDAP from ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"On the ASA, this is regularly achieved through the assignment of different group policies to different users. When LDAP authentication is in use, this can be achieved automatically with an LDAP attribute map. In order to use LDAP to assign a group policy to a user, you must map an LDAP attribute, such as the AD attribute memberOf to the Group-Policy attribute that is understood by the ASA. Once the attribute mapping is established, you must map the attribute value configured on the LDAP server to the name of a group policy on the ASA.&lt;/P&gt;&lt;P&gt;Note: The memberOf attribute corresponds to the group that the user is a a part of in the Active Directory. It is possible for a user to be a member of more than one group in the Active Directory. This causes multiple memberOf attributes to be sent by the server, but the ASA can only match one attribute to one group policy.""&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 10:11:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4607355#M1089930</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-05-10T10:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: integrate VPN with AD</title>
      <link>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4608060#M1089946</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks ,&amp;nbsp;&lt;BR /&gt;I did a group policy and Tunnel Group in ASA , could you please tell me what conf your asked me to shared&amp;nbsp;&lt;BR /&gt;in AD I configured NPS for new group&amp;nbsp;&lt;BR /&gt;Note : there are groups have already working fine and I tried to match all features either in AD or in ASA but still showing Login falied ,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 09:58:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrate-vpn-with-ad/m-p/4608060#M1089946</guid>
      <dc:creator>mautez_mah</dc:creator>
      <dc:date>2022-05-11T09:58:47Z</dc:date>
    </item>
  </channel>
</rss>

