12-08-2009 02:57 PM - edited 03-10-2019 04:50 PM
Hi all,
I have a cisco ASA 5505 which uses an LDAP AAA Server group as a user database.
My question is, by denying Dial -In access in Active Directory, or by controlling access using Remote Access Policy, will the ASA accept/deny logons? or do I have to set up 802.1x RADIUS authentication of some sorts?
Mario
12-09-2009 09:09 PM
Hi Mario,
You can control the VPN access to users using the Remote Dial-in permissions of the Active Directory. If you are using the ASA for VPN authentication using LDAP, you can check the following articles for the same:
For configuration using the ASDM: http://www.cisco.com/en/US/docs/security/asa/asa80/asdm60/selected_topics/enforce_AD.html#wp42080
For configuration using the CLI: http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008089149d.shtml
Regards,
Kush
12-10-2009 08:36 AM
Thanks Kush,
I'll check them out and get back to you....
Mario
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide