给你个参考:
aaa-server LDAP protocol ldap
aaa-server LDAP (INSIDE) host 10.10.10.1
ldap-base-dn DC=example,DC=com
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password *****
ldap-login-dn CN=svc_asavpn,OU=users,OU=chi,DC=example,DC=com
group-policy NoAccess internal
group-policy NoAccess attributes
vpn-simultaneous-logins 0
group-policy GRPPOL-RA-VPN internal
group-policy GRPPOL-RA-VPN attributes
dns-server value 10.10.10.1
vpn-simultaneous-logins 3
vpn-tunnel-protocol ssl-client
tunnel-group GRP-RA-VPN type remote-access
tunnel-group GRP-RA-VPN general-attributes
address-pool POOL-RA-VPN
authentication-server-group LDAP
default-group-policy NoAccess
ldap attribute-map MAP-ANYCONNECT-LOGIN
map-name memberOf Group-Policy
map-value memberOf CN=vpn_users,OU=groups,OU=chi,DC=example,DC=com GRPPOL-RA-VPN
aaa-server LDAP (INSIDE) host 10.10.10.1
ldap-attribute-map MAP-ANYCONNECT-LOGIN
还有,如果不行你可以debug 一下,命令如下:
debug ldap 255