cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

571
Views
0
Helpful
1
Replies
Michal Garcarz
Cisco Employee

Radius LDAP mapping for SGT

Hello Team,

It needs to be simple mistake, i had it working, now it's not working.

I authorize user in LDAP which hits authz rule having the following authorization profile:

 

Screen Shot 2018-09-19 at 23.36.53.png

Customer1_RODC is LDAP connection with physicalDeliveryOffice attribute:

Screen Shot 2018-09-19 at 23.38.37.png

Now when i do authorize user, i can see the following in auth logs:

Screen Shot 2018-09-19 at 23.36.32.png

Now - why value of physicalDeliveryOfficeName which is equal to 18 is not mapped ? And instead -01 is added to a string representation ?

 

It was working fine, but probably i have lost connectivity to LDAP, but i have readed it along with attribute.

Could you please confirm ?

 

Thanks,

Michal

 

1 ACCEPTED SOLUTION

Accepted Solutions
hslai
Cisco Employee

IIRC we need the entire RHS of cisco-av-pair as the value of the AD/LDAP attribute; e.g. Cisco:cisco-av-pair = AD1:description.

View solution in original post

1 REPLY 1
hslai
Cisco Employee

IIRC we need the entire RHS of cisco-av-pair as the value of the AD/LDAP attribute; e.g. Cisco:cisco-av-pair = AD1:description.

View solution in original post

Create
Recognize Your Peers
Polls
Which of these topics should we host an event in the Community?

Top Choice: pxGrid (39%)

Content for Community-Ad

ISE Webinars



Did you miss a previous ISE webinar?

CiscoISE YouTube Channel