Hello, everybody,
I have an office where ASA 5508 on the edge and users are allowed to browse Internet after they've logged with their AD credentials. Everything works fine, except one thing:
Some users work with laptops connected to wired network. Sometimes they attend meetings where they have to use Wifi connection. After they change wired connection to wireless, ASA restrict them Internet access. It happens until "account logon" event in AD occurs.
How could I manually initiate accout logon or configure ASA to allow a user to use wired and wireless network? I mean, without a long period of time to wait...
Here is my AAA configuration:
aaa-server LDAP protocol ldap
aaa-server LDAP (inside) host 10.39.1.11
ldap-base-dn DC=blablabla,DC=ru
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password *****
ldap-login-dn CN=RU-SCCMNetAccess,OU=IT,OU=.RU,DC=blablabla,DC=ru
server-type microsoft
ldap-attribute-map ANYCONNECT-LOGIN
aaa-server Duo-LDAP protocol ldap
aaa-server Duo-LDAP (outside) host
timeout 60
server-port 636
ldap-base-dn dc=
ldap-naming-attribute cn
ldap-login-password *****
ldap-login-dn dc=
ldap-over-ssl enable
server-type auto-detect
user-identity default-domain LOCAL
I could provide any information required.
Many thanks in advance,
Ilya