cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1367
Views
0
Helpful
2
Replies

AAA lookup to DC via connected site-to-site VPN

tonymurphy30
Level 1
Level 1

We have an ASA 5515 running 9.9(1) providing VPN connectivity only.

 

Remote users are first authenticated via an external RSA service, then a secondary check to our own Microsoft DC's is performed to assign the correct Group-Policy through the use of LDAP mappings.

 

We have two servers listed in the AAA server group for the LDAP mappings check, one is accessed via the ASA on our internal L3 network, however the backup server is located at a site which connects via a site-to-site VPN to the same ASA.

 

Connectivity works fine to the first DC, however the ASA's connectivity to the second DC (via the tunnel) is dropped by the firewall.

 

The protected networks for this S2S VPN does include the network of the inside interface of the ASA, but it seems that the specific interface address is not included in the S2S VPN, if i do a packet trace with an IP address just one number different then the flow is allowed and sent over the vpn, using the ASA's interface address, the flow is immediately denied.

 

Is there any specific settings to allow the physical ASA to utilise the site-to-site VPN?

 

1 Accepted Solution

Accepted Solutions

Resolved the issue, had to set the "management-access inside" command, as soon as this was enabled the ASA could do LDAP queries etc down the site to site VPN.

View solution in original post

2 Replies 2

Rahul Govindan
VIP Alumni
VIP Alumni

Source IP address of the LDAP request would be the interface where the route to the LDAP server points to. In your case, this should be the WAN/outside interface of the ASA (where S2S vpn is terminated). Try adding the Outside interface ip address of the ASA to the crypto ACL on both sides. 

Resolved the issue, had to set the "management-access inside" command, as soon as this was enabled the ASA could do LDAP queries etc down the site to site VPN.

Review Cisco Networking products for a $25 gift card