<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WEBVPN and AD group membership in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/webvpn-and-ad-group-membership/m-p/1192254#M956695</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the suggestions.  I went with an LDAP solution, but ditched the member of requirment.  I just set up different aaa server-groups with different base DNs, since the accounts will be seperated by OUs anyhow.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I don't think I can use auto-signon with LDAP, correct?  Would I need to configure an SSO server if I wanted to have a signle sign-on solution for cifs shares?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for pointing me in the right direction. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Mar 2009 21:11:03 GMT</pubDate>
    <dc:creator>ryan.bachman</dc:creator>
    <dc:date>2009-03-11T21:11:03Z</dc:date>
    <item>
      <title>WEBVPN and AD group membership</title>
      <link>https://community.cisco.com/t5/network-security/webvpn-and-ad-group-membership/m-p/1192252#M956693</link>
      <description>&lt;P&gt;I desperately need some advice with my WEBVPN authentication design.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How would I restrict specific users to only connect to certain connection profile Aliases?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance. lets say I have GROUP A, GROUP B, and GROUP C as aliases, available on the drop-down menu of the SSL login screen.  In AD, I have 3 Security groups named the same.  How do I ensure that only members of the group A security group can authenticate to the GROUP A connection profile, and not the others.  Ideally, I would like to accomplish this with Radius authentication, but I couldn't find an attribute that was passed along that I can prequalify against.  Any and all suggestions are appreciated.  Thanks.  &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:20:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webvpn-and-ad-group-membership/m-p/1192252#M956693</guid>
      <dc:creator>ryan.bachman</dc:creator>
      <dc:date>2020-02-21T11:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: WEBVPN and AD group membership</title>
      <link>https://community.cisco.com/t5/network-security/webvpn-and-ad-group-membership/m-p/1192253#M956694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use ldap mapping to authenticate your users against AD with ldap, and retrieve the memberOf value and map this to the IETF-Class value that the ASA understands, this to enable group lock, which will only allow users belonging to a specific tunnel group/group policy to connect to that tunnel group/group policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Mar 2009 16:32:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webvpn-and-ad-group-membership/m-p/1192253#M956694</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-03-11T16:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: WEBVPN and AD group membership</title>
      <link>https://community.cisco.com/t5/network-security/webvpn-and-ad-group-membership/m-p/1192254#M956695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the suggestions.  I went with an LDAP solution, but ditched the member of requirment.  I just set up different aaa server-groups with different base DNs, since the accounts will be seperated by OUs anyhow.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I don't think I can use auto-signon with LDAP, correct?  Would I need to configure an SSO server if I wanted to have a signle sign-on solution for cifs shares?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for pointing me in the right direction. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Mar 2009 21:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webvpn-and-ad-group-membership/m-p/1192254#M956695</guid>
      <dc:creator>ryan.bachman</dc:creator>
      <dc:date>2009-03-11T21:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: WEBVPN and AD group membership</title>
      <link>https://community.cisco.com/t5/network-security/webvpn-and-ad-group-membership/m-p/1192255#M956696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mhhh I am not a Windows guy, but one of the requirements is for your system to support NTLM v1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008067e9ff.shtml#req" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008067e9ff.shtml#req&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Mar 2009 23:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webvpn-and-ad-group-membership/m-p/1192255#M956696</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-03-11T23:06:01Z</dc:date>
    </item>
  </channel>
</rss>

