02-08-2021 03:17 AM
Hello,
I have 9200 IOS XE 16.x.x and 17.x.x catalysts on which I would like to set up CLI user authentication by LDAP / LDAPS server.
My question is whether this is possible with only an LDAP server without any AAA server (TACACS +, Radius)?
I have seen some documents but I am confused because according to some it seems that this is possible with the new IOS versions.
Can you please answer this question, the answer has a strong impact on my architecture.
Thank you for your efforts .
Best regards
02-08-2021 04:35 AM
Most use case use Radius/ TACACS (back ground with LADP as authentication) - as per our expereince in the real deployment.
You are right some documents says yes/no, but again no one have clear post or test results, if this is your requirement, you can test as PoC before offering any solution or learn what is missing.
when i did some digging past this what i have URL (not sure if this help you )
02-09-2021 01:18 AM - edited 02-09-2021 01:24 AM
this configuration guide says it is possible, but a catch...... using IPv6
How to Configure IPv6 Support for LDAP
Hmmmm..... link is for 9600, (9x00 series...) but same guide for 9200 does not show LDAP
02-25-2024 03:39 AM
Im facing the same issue ATM, did you manage to find any solution?
were you successful doing the authentication only LDAP server without any other AAA server?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide