<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD 1150 LDAPs not working on Remote Access VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247556#M1118825</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;&amp;nbsp; I'm trying to allow user to change their AD password on the AnyConnect client when they are working from home. I think it is a requirement to hava LDAP ove SSL to accomplish that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using AAA and Client Certificate to accomplish the MFA.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jan 2025 15:47:04 GMT</pubDate>
    <dc:creator>the_flyps</dc:creator>
    <dc:date>2025-01-15T15:47:04Z</dc:date>
    <item>
      <title>FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247474#M1118798</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I already have configure the ldap and it is working on VPN perfectly, but when I configure LDAPs i'm getting login error with the following error on the logs:&lt;/P&gt;&lt;P&gt;"AAA unable to complete the request error reason memory error"&lt;/P&gt;&lt;P&gt;I have done the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Test directory configuration (t&lt;SPAN&gt;est connection succeeded&lt;/SPAN&gt;)&lt;/LI&gt;&lt;LI&gt;Test the Realm Configuration (&lt;SPAN&gt;AD Join test succeed&lt;/SPAN&gt;)&lt;/LI&gt;&lt;LI&gt;CA enrollment is fine&lt;/LI&gt;&lt;LI&gt;Users download is working too&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If i rollback to ldap without SSL it starts working fine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 12:56:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247474#M1118798</guid>
      <dc:creator>the_flyps</dc:creator>
      <dc:date>2025-01-15T12:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247493#M1118799</link>
      <description>&lt;P&gt;Share output of&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Debug ldap 255&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 13:47:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247493#M1118799</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-15T13:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247552#M1118823</link>
      <description>&lt;P&gt;Why are you using LDAP at all?&amp;nbsp; What is the MFA strategy here?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 15:37:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247552#M1118823</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-01-15T15:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247553#M1118824</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp; so far i have this logs:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;%FTD-auth-2-113022: AAA Marking LDAP server Mydomain.local in aaa-server group Mydomain as FAILED\cf1\highlight2 &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;%FTD-auth-2-113022: AAA Marking LDAP server mydomain2.local in aaa-server group Mydomain as FAILED\cf1\highlight2 &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;%FTD-auth-6-113013: AAA unable to complete the request Error : reason = Memory error : user = user\cf1\highlight2 &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know if this other part have something to do with the issue.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;New request Session, context 0x000015487ec50de8, reqType = Authentication&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;lt;167&amp;gt;:Jan 15 15:35:23 UTC: %FTD-sys-7-711001: [3539578] Fiber started&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;lt;167&amp;gt;:Jan 15 15:35:23 UTC: %FTD-sys-7-711001: [3539578] Failed to convert ip address 0.0.0.0&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;lt;167&amp;gt;:Jan 15 15:35:23 UTC: %FTD-sys-7-711001: [3539578] Fiber exit Tx=0 bytes Rx=0 bytes, status=-2&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;lt;167&amp;gt;:Jan 15 15:35:23 UTC: %FTD-sys-7-711001: [3539578] Session End&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 15:37:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247553#M1118824</guid>
      <dc:creator>the_flyps</dc:creator>
      <dc:date>2025-01-15T15:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247556#M1118825</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;&amp;nbsp; I'm trying to allow user to change their AD password on the AnyConnect client when they are working from home. I think it is a requirement to hava LDAP ove SSL to accomplish that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using AAA and Client Certificate to accomplish the MFA.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 15:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247556#M1118825</guid>
      <dc:creator>the_flyps</dc:creator>
      <dc:date>2025-01-15T15:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247559#M1118826</link>
      <description>&lt;P&gt;To me it does seem a buggy behaviour and probably you are hitting a software bug. What version of software you are running?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 15:48:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247559#M1118826</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2025-01-15T15:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247562#M1118827</link>
      <description>&lt;P&gt;I will send you PM&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 15:50:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247562#M1118827</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-15T15:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247563#M1118828</link>
      <description>&lt;P&gt;Yeah IMHO that's not really MFA.&amp;nbsp; MFA would be a token, SMS, push notification, etc. in addition to the Certificate and credential.&amp;nbsp; Certificate + SAML would be far more secure and scalable than Certificate + LDAP.&amp;nbsp; I would highly recommend doing this through a SAML flow instead.&amp;nbsp; The user can reset their password through the IDP directly within the SAML flow instead of relying on exposing your VPN headend directly to LDAP (which I assume is an AD server).&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 15:52:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247563#M1118828</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-01-15T15:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247569#M1118830</link>
      <description>&lt;P&gt;Do you think DUO with SAML will work?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 16:01:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247569#M1118830</guid>
      <dc:creator>the_flyps</dc:creator>
      <dc:date>2025-01-15T16:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247573#M1118832</link>
      <description>&lt;P&gt;i'm Using 7.4.2 on the FMC and 7.4.2 on the FTD&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 16:04:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247573#M1118832</guid>
      <dc:creator>the_flyps</dc:creator>
      <dc:date>2025-01-15T16:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247575#M1118833</link>
      <description>Why not 7.4.2.1?&lt;BR /&gt;</description>
      <pubDate>Wed, 15 Jan 2025 16:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247575#M1118833</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-01-15T16:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247576#M1118834</link>
      <description>Yes.&lt;BR /&gt;</description>
      <pubDate>Wed, 15 Jan 2025 16:07:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247576#M1118834</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2025-01-15T16:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247586#M1118836</link>
      <description>&lt;P&gt;&lt;A href="https://bst.cisco.com/quickview/bug/CSCwd25602" target="_blank"&gt;https://bst.cisco.com/quickview/bug/CSCwd25602&lt;/A&gt; &amp;lt;&amp;lt;- check this&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 16:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247586#M1118836</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-15T16:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247592#M1118837</link>
      <description>&lt;P&gt;I will plan the upgrade to the cisco suggested version, I think it is the 7.4.2.1 and let you guys knows. It seems a buggy behavior&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 16:42:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247592#M1118837</guid>
      <dc:creator>the_flyps</dc:creator>
      <dc:date>2025-01-15T16:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247596#M1118838</link>
      <description>&lt;P&gt;I already have duo with the radius gateway with a different RAVPN profile, I will test moving to SAML it seems the better and scalable option.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 16:46:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5247596#M1118838</guid>
      <dc:creator>the_flyps</dc:creator>
      <dc:date>2025-01-15T16:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1150 LDAPs not working on Remote Access VPN</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5248097#M1118863</link>
      <description>&lt;P&gt;As &lt;A href="https://bst.cisco.com/quickview/bug/CSCwd25602" target="_blank" rel="nofollow noopener noreferrer"&gt;https://bst.cisco.com/quickview/bug/CSCwd25602&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;it was a misleading message. it was a DNS problem on the FTD. on the FMC was good but the FTD could not reach the domain controller by the name.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This was the error i identify:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;New request Session, context 0x000015487ec50de8, reqType = Authentication&lt;BR /&gt;%FTD-sys-7-711001: [3539578] Fiber started&lt;BR /&gt;%FTD-sys-7-711001: [3539578] Failed to convert ip address 0.0.0.0&lt;BR /&gt;%FTD-sys-7-711001: [3539578] Fiber exit Tx=0 bytes Rx=0 bytes, status=-2&lt;BR /&gt;%FTD-sys-7-711001: [3539578] Session End&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you Guys&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2025 13:41:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1150-ldaps-not-working-on-remote-access-vpn/m-p/5248097#M1118863</guid>
      <dc:creator>the_flyps</dc:creator>
      <dc:date>2025-01-16T13:41:12Z</dc:date>
    </item>
  </channel>
</rss>

