cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
594
Views
0
Helpful
1
Replies

LDAP and ACS Configuration

federico29
Level 1
Level 1

I have setup my LDAP database configuration with the following attributes in the fields:

User Directory Subtree=OU=7612,DC=1,DC=2

Group Directory Subtree=OU=7612,DC=1,DC=2

UserOjectType=subtree

UserObjectClass=subtree

GroupObjectType=dn

GroupObjectClass=top

GroupAttributeName=top

With this configuration, i can get my ACS to talk to my LDAP server. I am trying to setup PIX515E w/RADIUS authen to ACS using LDAP. When i click on Group Mappings, i see all of my network usernames from my domain. I setup RADIUS shared secret key on Firewall with ACS Static IP address. When i set my VPN Pool with XAuth Server as RADIUS, i cannot get authentication. I can VPN into my network, but it will not accept my username and pwd? What am i missing, i cannot figure out.

Thanks,

1 Reply 1

didyap
Level 6
Level 6

When AAA is used, the PIXFirewall must have a server group for each AAA protocol enabled. The aaa-server command is used both to define server groups and to add specific AAA servers to a server group. You can have up to 16 server groups on the PIXFirewall.

http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_guide_chapter09186a00801fd7e3.html#wp634909