03-30-2006 02:34 AM - edited 02-21-2020 10:15 AM
Hi all,
Does anyone know if ASA support more than 1 authentication server at the same time? I want to authenticate WebVPN users by LDAP and RSA SecurID. I mean WebVPN users have to enter the LDAP username, password and SecurID tokencode when login.
Please advice.
Thanks for advance,
Nitass
04-05-2006 07:15 AM
I have not heard such authentication mechanisms, at the same level of authentication. May be it is possible to use two different authentication servers for two different levels, that is, first get authenticated by LDAP server and then again get authenticated with SecurIP Token. Has anyone implemented this two level authentication?
02-12-2008 09:24 AM
Yes this is working
but you need to have the same user database in the RSA appliance and Ldap server
the passwork will be only checked in the primary auth server
anyway the ldap config is tricky if you want to use groups too, you need to map some Ldap attribute in the Asa, there's a doc somewhere in the Cisco tech support to do that.
good luck
Johann
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide