<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello anersantana,I've done in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ldap-atribute-map/m-p/2518234#M237855</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Hello anersantana,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;I've done this many times. Please use the below listed configuration and let me know how it goes.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Configuration for restricting access to a particular windows group on AD&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;group-policy noaccess internal&lt;BR /&gt;group-policy noaccess attributes&lt;BR /&gt;&amp;nbsp;vpn-simultaneous-logins 0&lt;BR /&gt;&amp;nbsp;address-pools none&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;&amp;nbsp;ldap attribute-map LDAP-MAP&lt;BR /&gt;&amp;nbsp; map-name &amp;nbsp;memberOf IETF-Radius-Class&lt;BR /&gt;&amp;nbsp; map-value memberOf &amp;lt;DN of the VPN group&amp;gt; &amp;lt;Group Policy Name&amp;gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;aaa-server LDAP-AD protocol ldap&lt;BR /&gt;aaa-server LDAP-AD host &amp;lt;IP-of-Windows-AD&amp;gt;&lt;BR /&gt;&amp;nbsp;server-port 389&lt;BR /&gt;&amp;nbsp;ldap-base-dn &amp;lt;AD base DN&amp;gt;&lt;BR /&gt;&amp;nbsp;ldap-scope subtree&lt;BR /&gt;&amp;nbsp;ldap-naming-attribute sAMAccountName&lt;BR /&gt;&amp;nbsp;ldap-login-dn &amp;lt;login user DN&amp;gt;&lt;BR /&gt;&amp;nbsp;ldap-login-password &amp;lt;password for login user DN&amp;gt;&lt;BR /&gt;&amp;nbsp;server-type microsoft&lt;BR /&gt;&amp;nbsp;ldap-attribute-map LDAP-MAP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;group-policy &amp;lt;Group Policy Name&amp;gt; internal&lt;BR /&gt;group-policy &amp;lt;Group Policy Name&amp;gt; attributes&lt;BR /&gt;&amp;nbsp;vpn-simultaneous-logins 3&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol IPSec l2tp-ipsec ...&lt;BR /&gt;&amp;nbsp;address-pools value &amp;lt;Address Pool Name&amp;gt;&lt;BR /&gt;&amp;nbsp;.....&lt;BR /&gt;&amp;nbsp;.....&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;tunnel-group &amp;lt;Tunnel group name&amp;gt; type remote-access&lt;BR /&gt;tunnel-group &amp;lt;Tunnel group name&amp;gt; general-attributes&lt;BR /&gt;&amp;nbsp;authentication-server-group LDAP-AD&lt;BR /&gt;&amp;nbsp;default-group-policy noaccess&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;** Do rate helpful posts **&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 07 Jun 2014 22:25:42 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2014-06-07T22:25:42Z</dc:date>
    <item>
      <title>ldap atribute map</title>
      <link>https://community.cisco.com/t5/network-security/ldap-atribute-map/m-p/2518233#M237853</link>
      <description>&lt;P&gt;I ve read so far like 100 different Discussion, about how to restring vpn users &amp;nbsp;authentication to some active directory. If not part of the Active Directory Group call "vpn-group", cant connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;I cannot find any guide that allow me to log users only if is on group. Some article say I have to use&amp;nbsp;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;IETF-Radius-Class, other Group_Policy, on Ldap attribute map.&lt;SPAN style="font-size:14px;"&gt;&amp;nbsp;Actually Im confuse cuz some articles like this:&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/98634-asa-ldap-group-pol.html&amp;nbsp;" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/98634-asa-ldap-group-pol.html&amp;nbsp;&lt;/A&gt; but on other article say use Group_policy instead. I wish someone give me someone who has really done this. Give me some pdf guide or something alike.&amp;nbsp;&lt;/P&gt;&lt;P&gt;: ( I have one week try to do this and just does not work. It like is not seen atributte map, Cuz all users are been authenticated. I have asa version 9.1.2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need help!!!!!!!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:17:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ldap-atribute-map/m-p/2518233#M237853</guid>
      <dc:creator>anersantana</dc:creator>
      <dc:date>2019-03-12T04:17:33Z</dc:date>
    </item>
    <item>
      <title>Hello anersantana,I've done</title>
      <link>https://community.cisco.com/t5/network-security/ldap-atribute-map/m-p/2518234#M237855</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Hello anersantana,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;I've done this many times. Please use the below listed configuration and let me know how it goes.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Configuration for restricting access to a particular windows group on AD&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;group-policy noaccess internal&lt;BR /&gt;group-policy noaccess attributes&lt;BR /&gt;&amp;nbsp;vpn-simultaneous-logins 0&lt;BR /&gt;&amp;nbsp;address-pools none&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;&amp;nbsp;ldap attribute-map LDAP-MAP&lt;BR /&gt;&amp;nbsp; map-name &amp;nbsp;memberOf IETF-Radius-Class&lt;BR /&gt;&amp;nbsp; map-value memberOf &amp;lt;DN of the VPN group&amp;gt; &amp;lt;Group Policy Name&amp;gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;aaa-server LDAP-AD protocol ldap&lt;BR /&gt;aaa-server LDAP-AD host &amp;lt;IP-of-Windows-AD&amp;gt;&lt;BR /&gt;&amp;nbsp;server-port 389&lt;BR /&gt;&amp;nbsp;ldap-base-dn &amp;lt;AD base DN&amp;gt;&lt;BR /&gt;&amp;nbsp;ldap-scope subtree&lt;BR /&gt;&amp;nbsp;ldap-naming-attribute sAMAccountName&lt;BR /&gt;&amp;nbsp;ldap-login-dn &amp;lt;login user DN&amp;gt;&lt;BR /&gt;&amp;nbsp;ldap-login-password &amp;lt;password for login user DN&amp;gt;&lt;BR /&gt;&amp;nbsp;server-type microsoft&lt;BR /&gt;&amp;nbsp;ldap-attribute-map LDAP-MAP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;group-policy &amp;lt;Group Policy Name&amp;gt; internal&lt;BR /&gt;group-policy &amp;lt;Group Policy Name&amp;gt; attributes&lt;BR /&gt;&amp;nbsp;vpn-simultaneous-logins 3&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol IPSec l2tp-ipsec ...&lt;BR /&gt;&amp;nbsp;address-pools value &amp;lt;Address Pool Name&amp;gt;&lt;BR /&gt;&amp;nbsp;.....&lt;BR /&gt;&amp;nbsp;.....&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;tunnel-group &amp;lt;Tunnel group name&amp;gt; type remote-access&lt;BR /&gt;tunnel-group &amp;lt;Tunnel group name&amp;gt; general-attributes&lt;BR /&gt;&amp;nbsp;authentication-server-group LDAP-AD&lt;BR /&gt;&amp;nbsp;default-group-policy noaccess&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;** Do rate helpful posts **&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Jun 2014 22:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ldap-atribute-map/m-p/2518234#M237855</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-06-07T22:25:42Z</dc:date>
    </item>
  </channel>
</rss>

