<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Per Cisco: &amp;quot;AAA does not in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-configure-ldap-on-3750x/m-p/2423331#M919892</link>
    <description>&lt;P&gt;Per Cisco:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"AAA does not support using an LDAP method for interactive login authentication."&lt;/P&gt;</description>
    <pubDate>Wed, 21 May 2014 20:25:26 GMT</pubDate>
    <dc:creator>kceleslie</dc:creator>
    <dc:date>2014-05-21T20:25:26Z</dc:date>
    <item>
      <title>How to configure LDAP on 3750x</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-ldap-on-3750x/m-p/2423330#M919891</link>
      <description>&lt;P&gt;I've done some reading and it looks like it is possible to configure a cisco switch to use LDAP authentication but I'm struggling on what to do next. I rather not use RADIUS or tacacs+ as they both require additional configuration on the LDAP server. Am I correct that IOS can just use LDAP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been using this guide, but can only seem to get halfway there.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/ios/sec_user_services/configuration/guide/convert/aaa_ldap/sec_cfg_ldap.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/ios/sec_user_services/configuration/guide/convert/aaa_ldap/sec_cfg_ldap.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using Version 15.0(2)SE6 on a 3750X ip based switch and my LDAP server is a Windows 2008 R2 box. Here is what i have so far:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server ldap DOMAIN&lt;BR /&gt;&amp;nbsp;server mydomain.com&lt;/P&gt;&lt;P&gt;ldap attribute-map NetworkAdmins&lt;BR /&gt;!&lt;BR /&gt;ldap server mydomain.com&lt;BR /&gt;&amp;nbsp;ipv4 10.0.1.10&lt;BR /&gt;&amp;nbsp;transport port 636&lt;BR /&gt;&amp;nbsp;bind authenticate root-dn "cn=ldap_svc,ou=service accounts,out=users,ou=mydomain.com,dc=mydomain,dc=com" password 7 PASSWORD&lt;BR /&gt;&amp;nbsp;base-dn ou=users,ou=mydomain.com,dc=mydomain,dc=com&lt;BR /&gt;&amp;nbsp;mode secure&lt;BR /&gt;&amp;nbsp;authentication bind-first&lt;BR /&gt;&amp;nbsp;authentication compare&lt;/P&gt;&lt;P&gt;If I’m understanding this correctly I have to configure an ldap server, then tell aaa to use that ldap server. I think I need to configure an ldap attribute-map but cant figure out the syntax. How do I tell it to use a specific group and how to I configure ssh or the console to use ldap?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-ldap-on-3750x/m-p/2423330#M919891</guid>
      <dc:creator>kceleslie</dc:creator>
      <dc:date>2020-02-21T13:11:11Z</dc:date>
    </item>
    <item>
      <title>Per Cisco: "AAA does not</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-ldap-on-3750x/m-p/2423331#M919892</link>
      <description>&lt;P&gt;Per Cisco:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"AAA does not support using an LDAP method for interactive login authentication."&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2014 20:25:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-ldap-on-3750x/m-p/2423331#M919892</guid>
      <dc:creator>kceleslie</dc:creator>
      <dc:date>2014-05-21T20:25:26Z</dc:date>
    </item>
  </channel>
</rss>

