07-20-2015 01:54 PM - edited 03-11-2019 11:18 PM
Hi As we know, Cisco firewall ASA needs to contact a lot username in database constantly. and the ASA can not hold all of the username. I wonder how ASA associate these usernames in Windows server through ASDM (I do not mean aaa server)? I am managing Anyconnect VPN. So, there are a lot user that need to be managed in ASA
Solved! Go to Solution.
07-20-2015 02:57 PM
The ASA validates the username at logon time via the authentication (aaa process). As long as the session is active, it keeps a record of what user is assigned what IP address.
If you are using the identity firewall features (i.e. usernames in access-list entries), the ASA is additionally communicating with AD for that, potentially via AD Agent (deprecated) or CDA.
07-20-2015 02:57 PM
The ASA validates the username at logon time via the authentication (aaa process). As long as the session is active, it keeps a record of what user is assigned what IP address.
If you are using the identity firewall features (i.e. usernames in access-list entries), the ASA is additionally communicating with AD for that, potentially via AD Agent (deprecated) or CDA.
07-23-2015 02:30 PM
Good answer! Thank you
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide