<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA and LDAP authorization in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-and-ldap-authorization/m-p/1085492#M418981</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The LDAP authorization attributes is not only for predefined group policy. You can push many attributes as per your requirement. As you want to push ACL on per user basis, that would be defined under "Cisco-AV-Pair". But again, in order to do that, you need to go through the document, and configure/add/edit your LDAP schema, so that it can have a security appliance authorization schema [object class (User-Authorization)], and all the listed attributes need to be added (all or some depending on your need) under this object class.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can be done using the attributes is, I guess, self explanatory. Please refer to table,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/extsvr.html#wp1629915" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/extsvr.html#wp1629915&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are looking for ldif file that needs to be created, you find an example file in this document. Go to the heading "Example Security Appliance Authorization Schema". You may want to get some help from an LDAP expert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But to push authorization attributes from LDAP server to ASA, you needs to add the LDAP authorization attributes in your LDAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if it helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 31 Aug 2008 16:45:06 GMT</pubDate>
    <dc:creator>Premdeep Banga</dc:creator>
    <dc:date>2008-08-31T16:45:06Z</dc:date>
    <item>
      <title>ASA and LDAP authorization</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-ldap-authorization/m-p/1085489#M418971</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I'm looking for the way to download user profiles for ASA (both IPSec and SSL) from LDAP server.&lt;/P&gt;&lt;P&gt;Quite similar to what it's possible to do with RADIUS ip-acl and webvpn-acl attributes.&lt;/P&gt;&lt;P&gt;Authentication works, I just need to limit access per user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2020 07:18:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-ldap-authorization/m-p/1085489#M418971</guid>
      <dc:creator>v.kirillov</dc:creator>
      <dc:date>2020-02-22T07:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA and LDAP authorization</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-ldap-authorization/m-p/1085490#M418976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would be required to define a security appliance authorization schema, and then use the attributes that you want,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring an External LDAP Server:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/extsvr.html#wp1577162" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/extsvr.html#wp1577162&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if it helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Aug 2008 05:38:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-ldap-authorization/m-p/1085490#M418976</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2008-08-31T05:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA and LDAP authorization</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-ldap-authorization/m-p/1085491#M418978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;I understand it. However, what I found as examples only maps predefined group-policy, accepts or denies the access etc. So, not really the ACL as I need to apply per-user.&lt;/P&gt;&lt;P&gt;Do you have more examples?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Aug 2008 09:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-ldap-authorization/m-p/1085491#M418978</guid>
      <dc:creator>v.kirillov</dc:creator>
      <dc:date>2008-08-31T09:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA and LDAP authorization</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-ldap-authorization/m-p/1085492#M418981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The LDAP authorization attributes is not only for predefined group policy. You can push many attributes as per your requirement. As you want to push ACL on per user basis, that would be defined under "Cisco-AV-Pair". But again, in order to do that, you need to go through the document, and configure/add/edit your LDAP schema, so that it can have a security appliance authorization schema [object class (User-Authorization)], and all the listed attributes need to be added (all or some depending on your need) under this object class.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can be done using the attributes is, I guess, self explanatory. Please refer to table,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/extsvr.html#wp1629915" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/extsvr.html#wp1629915&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are looking for ldif file that needs to be created, you find an example file in this document. Go to the heading "Example Security Appliance Authorization Schema". You may want to get some help from an LDAP expert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But to push authorization attributes from LDAP server to ASA, you needs to add the LDAP authorization attributes in your LDAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if it helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Aug 2008 16:45:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-ldap-authorization/m-p/1085492#M418981</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2008-08-31T16:45:06Z</dc:date>
    </item>
  </channel>
</rss>

