<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC AD SSO Mapping Rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-ad-sso-mapping-rules/m-p/1298630#M824149</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check with Auth Test to see what attributes are being returned with your LDAP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 25 Oct 2009 03:06:10 GMT</pubDate>
    <dc:creator>Faisal Sehbai</dc:creator>
    <dc:date>2009-10-25T03:06:10Z</dc:date>
    <item>
      <title>NAC AD SSO Mapping Rules</title>
      <link>https://community.cisco.com/t5/network-security/nac-ad-sso-mapping-rules/m-p/1298629#M824129</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;I've configured AD SSO and chose "ldap lookup server" to none and everything worked fine and put all users to default role in AD SSO configuration. &lt;/P&gt;&lt;P&gt;Now I need to configure different user role based on user membership in AD. So I configured lookup server and add it to AD SSO server. then confiured mapping rules and put "memberof" attribute in LDAP. But it doesn't work. still all users login to the default role, and it seems LDAP lookup server and mapping rules doesn't receive memberof attribute from AD. &lt;/P&gt;&lt;P&gt;any suggestion would be very appreciated. &lt;/P&gt;&lt;P&gt;thanks &lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:45:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-ad-sso-mapping-rules/m-p/1298629#M824129</guid>
      <dc:creator>alex goshtaei</dc:creator>
      <dc:date>2020-02-21T11:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: NAC AD SSO Mapping Rules</title>
      <link>https://community.cisco.com/t5/network-security/nac-ad-sso-mapping-rules/m-p/1298630#M824149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check with Auth Test to see what attributes are being returned with your LDAP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Oct 2009 03:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-ad-sso-mapping-rules/m-p/1298630#M824149</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2009-10-25T03:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: NAC AD SSO Mapping Rules</title>
      <link>https://community.cisco.com/t5/network-security/nac-ad-sso-mapping-rules/m-p/1298631#M824159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faisal, &lt;/P&gt;&lt;P&gt;in auth test tab, I don't see AD SSO or lookup server as provider. &lt;/P&gt;&lt;P&gt;thanks again, &lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Oct 2009 21:30:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-ad-sso-mapping-rules/m-p/1298631#M824159</guid>
      <dc:creator>alex goshtaei</dc:creator>
      <dc:date>2009-10-26T21:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: NAC AD SSO Mapping Rules</title>
      <link>https://community.cisco.com/t5/network-security/nac-ad-sso-mapping-rules/m-p/1298632#M824205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depends on the version if they would be visible or not, but you can also setup a LDAP lookup server with the same settings as your lookup server and do an auth test with that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Oct 2009 23:14:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-ad-sso-mapping-rules/m-p/1298632#M824205</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2009-10-26T23:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAC AD SSO Mapping Rules</title>
      <link>https://community.cisco.com/t5/network-security/nac-ad-sso-mapping-rules/m-p/1298633#M824222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check your string, it must be "memberOf", use capital "O".  also, there must be no spaces in between your search strings, e.g. CN=abcd,DN=abcd&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Oct 2009 06:02:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-ad-sso-mapping-rules/m-p/1298633#M824222</guid>
      <dc:creator>rc.castillo</dc:creator>
      <dc:date>2009-10-27T06:02:16Z</dc:date>
    </item>
  </channel>
</rss>

