<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyconnect + LDAP AAA - not getting groups for some? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-ldap-aaa-not-getting-groups-for-some/m-p/2189383#M361422</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had to look back as to when I posted this.&amp;nbsp; We upgraded to 9.0, etc and currently are running 9.13-2.&amp;nbsp;&amp;nbsp; In the spring we went thru a massive cutover of clients to sslvpn instead of open RDP.&amp;nbsp; We ran into this about 1/3rd of the places.&amp;nbsp;&amp;nbsp; We opened a TAC case and they found when running LDAP browser, attributes were NOT showing up in AD queries.&amp;nbsp;&amp;nbsp; We opened a Microsoft case and they did not like the LDAP browser cisco was using and used their own.&amp;nbsp;&amp;nbsp; Using their own, they showed the group attributes were showing up.&amp;nbsp; Personally, I've known Microsoft to be a pain in their support calls.&amp;nbsp; LDAP is LDAP as far as a group attribute query.&amp;nbsp;&amp;nbsp; Anyway, I digress.&amp;nbsp;&amp;nbsp; Microsoft said it was fine and cisco consistently showed thru various browsers that it wasn't working with AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But interesting you asked if i had resolved it.&amp;nbsp; I've not messed with it since spring, and then I decided to test again this past weekend (6+ months since the issue)..&amp;nbsp;&amp;nbsp; And i'll be darn if it didnt work everywhere i was having issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best I can say is it's either the 9.13-2 version we're running or a MS update that occurred in the last 6 months.&amp;nbsp; We've ran 9.0x and 9.12 way back when testing and upgrading client ASAs - problem still existed.&amp;nbsp; We put on 9.13-2 maybe 30 days ago?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know this isn't a definitive answer, but perhaps there's MS updates you're missing, or perhaps the issue was on Cisco's side, whereas 9.13-2 has resolved the mysterious issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Nov 2013 23:57:35 GMT</pubDate>
    <dc:creator>Jeff Cooper</dc:creator>
    <dc:date>2013-11-26T23:57:35Z</dc:date>
    <item>
      <title>Anyconnect + LDAP AAA - not getting groups for some?</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-ldap-aaa-not-getting-groups-for-some/m-p/2189381#M361417</link>
      <description>&lt;P&gt;I have a couple hundred ASAs out in the field and they all started having the same problem.&amp;nbsp; They use anyconnect with LDAP authentication.&amp;nbsp; I use an attribute map and successfully get users into their group-policy based on their active-directory group membership.&amp;nbsp; Been working great for a while...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UNTIL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;recently...&amp;nbsp;&amp;nbsp; Recently, I'm getting some environments where windows 2012 has been added to the domain.&amp;nbsp;&amp;nbsp; Any new user I create in these environments, will not pull group membership in LDAP.&amp;nbsp; Says login failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specifically: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm running 8.45.&amp;nbsp;&amp;nbsp; I run ldap debug, and for an existing user, they login and debug shows the complete group membership from Active Directory.&amp;nbsp; And consequently, they successfully get their group-policy assignment based on an AD group.&amp;nbsp; I enter in a new user, I don't get any group memberships in my LDAP results.&amp;nbsp; I create a new user by copying an existing user in AD and login with that - still no group membership info.&amp;nbsp; I've been working on this since October and I can't make any sense of it.&amp;nbsp; My ldap look account successfully binds and I get successful authentication for the user.&amp;nbsp;&amp;nbsp; But again, no group membership info.&amp;nbsp; I use a user that's existed in the domain, and I get all the group membership info and group-policy is assigned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have this same issue across multiple customers who've added windows 2012 to their domain.&amp;nbsp; Worked perfectly with new users, but now, new users dont show their group memberships.&amp;nbsp; I've configured AAA to authenticate against various domain controllers in the domain as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance would be appreciated.&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an ldap debug from an account I created by copying an account that successfuly authenticates (and pulls group memberships from ldap).&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Since I have had this working 100% across all our installations until about 5-6 months ago, I've not included a ldap debug of a successful anyconnect login.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[54] Session Start&lt;/P&gt;&lt;P&gt;[54] New request Session, context 0xd872610c, reqType = Authentication&lt;/P&gt;&lt;P&gt;[54] Fiber started&lt;/P&gt;&lt;P&gt;[54] Creating LDAP context with uri=ldap://10.0.0.5:3268&lt;/P&gt;&lt;P&gt;[54] Connect to LDAP server: &lt;/P&gt;&lt;P&gt;&lt;A href="ldap://10.0.0.5:3268" target="_blank"&gt;ldap://10.0.0.5:3268&lt;/A&gt; &lt;/P&gt;&lt;P&gt;, status = Successful&lt;/P&gt;&lt;P&gt;[54] supportedLDAPVersion: value = 3&lt;/P&gt;&lt;P&gt;[54] supportedLDAPVersion: value = 2&lt;/P&gt;&lt;P&gt;[54] Binding as &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:ASA-LDAP-LOOKUP@entre.local" target="_blank"&gt;ASA-LDAP-LOOKUP@entre.local&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[54] Performing Simple authentication for &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:ASA-LDAP-LOOKUP@entre.local" target="_blank"&gt;ASA-LDAP-LOOKUP@entre.local&lt;/A&gt; &lt;/P&gt;&lt;P&gt;to 10.0.0.5&lt;/P&gt;&lt;P&gt;[54] LDAP Search:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Base DN = [DC=entre,DC=local]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Filter&amp;nbsp; = [sAMAccountName=testtest]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Scope&amp;nbsp;&amp;nbsp; = [SUBTREE]&lt;/P&gt;&lt;P&gt;[54] User DN = [CN=testtest,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=Entre,DC=local]&lt;/P&gt;&lt;P&gt;[54] Talking to Active Directory server 10.0.0.5&lt;/P&gt;&lt;P&gt;[54] Reading password policy for testtest, dn:CN=testtest,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=Entre,DC=local&lt;/P&gt;&lt;P&gt;[54] Binding as testtest&lt;/P&gt;&lt;P&gt;[54] Performing Simple authentication for testtest to 10.0.0.5&lt;/P&gt;&lt;P&gt;[54] Processing LDAP response for user testtest&lt;/P&gt;&lt;P&gt;[54] Message (testtest):&lt;/P&gt;&lt;P&gt;[54] Authentication successful for testtest to 10.0.0.5&lt;/P&gt;&lt;P&gt;[54] Retrieved User Attributes:&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectClass: value = top&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectClass: value = person&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectClass: value = organizationalPerson&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectClass: value = user&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; cn: value = testtest&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; c: value = US&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; l: value = Chicago&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; st: value = IL&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; title: value = Cisco Manager&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; postalCode: value = 60601&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; givenName: value = testtest&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; distinguishedName: value = CN=testtest,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=Entre,DC=local&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; displayName: value = testtest&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; co: value = United States&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; department: value = Professional Services&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; company: value = Computer Solutions&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; publicDelegates: value = CN=ComputerSolutions,OU=Distribution Groups,OU=MyBusiness,DC=Entre,DC=local&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; publicDelegates: value = CN=Mike Broski,OU=Special,DC=Entre,DC=local&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; publicDelegates: value = CN=Beth Harris,OU=SBSUsers,OU=Users,OU=MyBusiness,DC=Entre,DC=local&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; mDBUseDefaults: value = TRUE&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; protocolSettings: value = OWA..1&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; protocolSettings: value = HTTP..1..1............&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; name: value = testtest&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectGUID: value = ....;.gF...?..}.&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; primaryGroupID: value = 513&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectSid: value = ............M....qp&amp;amp;|t.Zi...&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; sAMAccountName: value = testtest&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; sAMAccountType: value = 805306368&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; showInAddressBook: value = CN=All Users,CN=All Address Lists,CN=Address Lists Container,CN=ENTRE,CN=Microso&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; showInAddressBook: value = CN=Default Global Address List,CN=All Global Address Lists,CN=Address Lists Cont&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; userPrincipalName: value = &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:testtest@Entre.local" target="_blank"&gt;testtest@Entre.local&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectCategory: value = CN=Person,CN=Schema,CN=Configuration,DC=Entre,DC=local&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; msExchHomeServerName: value = /o=ENTRE/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/cn=Configuration/cn=&lt;/P&gt;&lt;P&gt;[54]&amp;nbsp;&amp;nbsp;&amp;nbsp; msExchUserAccountControl: value = 0&lt;/P&gt;&lt;P&gt;[54] Fiber exit Tx=572 bytes Rx=2597 bytes, status=1&lt;/P&gt;&lt;P&gt;[54] Session End&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-ldap-aaa-not-getting-groups-for-some/m-p/2189381#M361417</guid>
      <dc:creator>Jeff Cooper</dc:creator>
      <dc:date>2019-03-26T00:50:11Z</dc:date>
    </item>
    <item>
      <title>Anyconnect + LDAP AAA - not getting groups for some?</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-ldap-aaa-not-getting-groups-for-some/m-p/2189382#M361419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you found a solution to this problem? I got same problem with a new Windows2012 Installation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ldap gives groups only for Administrator user but not for newly created ones&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Nov 2013 23:46:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-ldap-aaa-not-getting-groups-for-some/m-p/2189382#M361419</guid>
      <dc:creator>pf</dc:creator>
      <dc:date>2013-11-26T23:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect + LDAP AAA - not getting groups for some?</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-ldap-aaa-not-getting-groups-for-some/m-p/2189383#M361422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had to look back as to when I posted this.&amp;nbsp; We upgraded to 9.0, etc and currently are running 9.13-2.&amp;nbsp;&amp;nbsp; In the spring we went thru a massive cutover of clients to sslvpn instead of open RDP.&amp;nbsp; We ran into this about 1/3rd of the places.&amp;nbsp;&amp;nbsp; We opened a TAC case and they found when running LDAP browser, attributes were NOT showing up in AD queries.&amp;nbsp;&amp;nbsp; We opened a Microsoft case and they did not like the LDAP browser cisco was using and used their own.&amp;nbsp;&amp;nbsp; Using their own, they showed the group attributes were showing up.&amp;nbsp; Personally, I've known Microsoft to be a pain in their support calls.&amp;nbsp; LDAP is LDAP as far as a group attribute query.&amp;nbsp;&amp;nbsp; Anyway, I digress.&amp;nbsp;&amp;nbsp; Microsoft said it was fine and cisco consistently showed thru various browsers that it wasn't working with AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But interesting you asked if i had resolved it.&amp;nbsp; I've not messed with it since spring, and then I decided to test again this past weekend (6+ months since the issue)..&amp;nbsp;&amp;nbsp; And i'll be darn if it didnt work everywhere i was having issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best I can say is it's either the 9.13-2 version we're running or a MS update that occurred in the last 6 months.&amp;nbsp; We've ran 9.0x and 9.12 way back when testing and upgrading client ASAs - problem still existed.&amp;nbsp; We put on 9.13-2 maybe 30 days ago?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know this isn't a definitive answer, but perhaps there's MS updates you're missing, or perhaps the issue was on Cisco's side, whereas 9.13-2 has resolved the mysterious issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Nov 2013 23:57:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-ldap-aaa-not-getting-groups-for-some/m-p/2189383#M361422</guid>
      <dc:creator>Jeff Cooper</dc:creator>
      <dc:date>2013-11-26T23:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect + LDAP AAA - not getting groups for some?</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-ldap-aaa-not-getting-groups-for-some/m-p/2189384#M361425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had 9.1.3 on the ASA an upgraded now to 9.13-2. Still same issue, no groups are shown with the users expect of the Administrator.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug ldap 255 shows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;16] Authentication successful for sdag to 192.168.20.80&lt;/P&gt;&lt;P&gt;[16] Retrieved User Attributes:&lt;/P&gt;&lt;P&gt;[16]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectClass: value = top&lt;/P&gt;&lt;P&gt;[16]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectClass: value = person&lt;/P&gt;&lt;P&gt;[16]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectClass: value = organizationalPerson&lt;/P&gt;&lt;P&gt;[16]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectClass: value = user&lt;/P&gt;&lt;P&gt;[16]&amp;nbsp;&amp;nbsp;&amp;nbsp; cn: value = sdag&lt;/P&gt;&lt;P&gt;[16]&amp;nbsp;&amp;nbsp;&amp;nbsp; distinguishedName: value = CN=sdag,OU=Lieferanten,OU=Users,OU=xxxx,DC=xxxx,DC=local&lt;/P&gt;&lt;P&gt;[16]&amp;nbsp;&amp;nbsp;&amp;nbsp; displayName: value = sdag&lt;/P&gt;&lt;P&gt;[16]&amp;nbsp;&amp;nbsp;&amp;nbsp; homeMTA: value = CN=Microsoft MTA,CN=SRVSBS01,CN=Servers,CN=erste administrative gruppe,CN=Admini&lt;/P&gt;&lt;P&gt;[16]&amp;nbsp;&amp;nbsp;&amp;nbsp; proxyAddresses: value = smtp:sdag@mail.xxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with Administrator&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[18] Message (Administrator): &lt;/P&gt;&lt;P&gt;[18] Authentication successful for Administrator to 192.168.20.80&lt;/P&gt;&lt;P&gt;[18] Retrieved User Attributes:&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectClass: value = top&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectClass: value = person&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectClass: value = organizationalPerson&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; objectClass: value = user&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; cn: value = Administrator&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; description: value = Vordefiniertes Konto f..r die Verwaltung des Computers bzw. der Dom..ne&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; distinguishedName: value = CN=Administrator,CN=Users,DC=xxxxx,DC=local&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; instanceType: value = 4&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; whenCreated: value = 20081201134058.0Z&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; whenChanged: value = 20131126141559.0Z&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; displayName: value = Administrator&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; uSNCreated: value = 12298&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp; memberOf: value = CN=G_SSLVPN,OU=Service,OU=Groups,OU=xxxx,DC=xxxx,DC=local&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mapped to Group-Policy: value = ssl_admin&lt;/P&gt;&lt;P&gt;[18]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mapped to LDAP-Class: value = ssl_admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I will ask our server guy to check the updates on this server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Nov 2013 00:28:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-ldap-aaa-not-getting-groups-for-some/m-p/2189384#M361425</guid>
      <dc:creator>pf</dc:creator>
      <dc:date>2013-11-27T00:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect + LDAP AAA - not getting groups for some?</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-ldap-aaa-not-getting-groups-for-some/m-p/2189385#M361427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; yeah have him check for updates and let me know..&amp;nbsp;&amp;nbsp; i'd like to know if it's a win update or whatnot..&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that's kind of what we were running into..&amp;nbsp; admin accounts in general seemed to work ok..&amp;nbsp;&amp;nbsp;&amp;nbsp; but then if you changed a user to an admin group, it was like the LDAP lookup didnt see the change and they still didnt work..&amp;nbsp;&amp;nbsp;&amp;nbsp; on the other hand, was like some long long established account would work, but newly created accounts wouldn't work..&amp;nbsp; yeah, really messed with the head &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so i was pleasantly surprised it just up and worked this weekend..&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Nov 2013 00:33:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-ldap-aaa-not-getting-groups-for-some/m-p/2189385#M361427</guid>
      <dc:creator>Jeff Cooper</dc:creator>
      <dc:date>2013-11-27T00:33:14Z</dc:date>
    </item>
  </channel>
</rss>

