cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

138
Views
0
Helpful
1
Replies
Beginner

LDAP fails over vti tunnel ipsec

Hello guys,

 

I have a site to site vpn tunnel route-based ikev2 between 2 asa's and I am trying to obtain aaa ldap for anyconnect. 

The topology is like this:

ASA1 <----------IPSEC-vti tunnel (working)--------> ASA2 (anyconnect config remote authentication with AD using ldap)

The main problem is that i can't add at source interface the virtual int "aaa-server LdapServers (Tunnel100???) host x.x.x.x", only the physical interfaces "aaa-server LdapServers (OUTSIDE) host x.x.x.x" . I added the physical interface where the tunnel has it's source, but no good, still error unreachable server. Can you please help?


The configuration is correct, other traffic works, tunnel is up.

1 REPLY 1
Highlighted
Beginner

Re: LDAP fails over vti tunnel ipsec

Hi,

 

I have the same problem and I couldn't find any solution to it.

 

There is a similar case but with firepower appliances described here:

https://community.cisco.com/t5/firepower/ftd-source-interface-for-ldap-queries/td-p/3711561

 

Should this be a limitation or a feature ? The fact that you cannot source LDAP queries via the VTI interface but only through a Physical one is limiting your choices.

Everyone's tags (5)