cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1760
Views
15
Helpful
7
Replies

LDAP authenticate

billybong
Level 1
Level 1

Hi All, i'm hoping someone can point me in the right direction

I can’t get the LDAP groups to work it just allows all domain users to authenticate. 

 

any help greatly appreciated 

2 Accepted Solutions

Accepted Solutions

@billybong 

If all users are authenticating when using LDAP groups, it sounds like you don't have the NOACCESS group policy defined, which does not permit logons. This group-policy would be applied when a user is not a member of a specified LDAP group.

 

Refer to the guide below.

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/91831-mappingsvctovpn.html#anc15

View solution in original post

7 Replies 7

balaji.bandi
Hall of Fame
Hall of Fame

what device is this and what code running?  - based on the information we can suggest the right documents.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

billybong
Level 1
Level 1

Hey Balaji thanks for replying

ASA5525 Version 9.12(4)7

anyconnect version 4.0.00051

Thanks balaji, i'll take a look and let you know how i get on 

@billybong 

If all users are authenticating when using LDAP groups, it sounds like you don't have the NOACCESS group policy defined, which does not permit logons. This group-policy would be applied when a user is not a member of a specified LDAP group.

 

Refer to the guide below.

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/91831-mappingsvctovpn.html#anc15

LDAP map is config correctly ? can we see the config ?

Thanks Guy's all fixed NOACCESS group policy needed redefining