cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
848
Views
5
Helpful
3
Replies

Anyconnect on IOS and LDAP

lap
Level 2
Level 2

Hi,

I would like to know if LDAP will be supported with Anyconnect in the coming IOS release ? When?

Best regards,

Laurent

3 Replies 3

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Laurent,

As far as I know it's still not supported, interestingly I was able to find cases where people were asking about this, but not related enhancement request to track progress.

Typically we use ACS (via RADIUS) with LDAP/AD backend.

Marcin

Hi Marcin,

Perfect. Thanks for your quick reply. I would like to ask you a last question. What is the advantage of having LDAP some feature so if anyway you can connec to AD via a Radius server?

Best regards,

Laurent

Laurent,

Not sure if this will answer your question.

Having [pure] LDAP is nice if you want to perform authentication and your user base is already populated in AD.

There are no middle steps, just query and reply.

The "problem" with LDAP especially based on AD is that all the information about user that is not primary (username and password I would consider primary) is stored in a way that does not allow easy facility to apply/map to networking.

On ASA to overcome this we have LDAP attribute mapping where we map attributes from LDAP to common RADIUS ones.

When using AD from ACS I beleive (note that I'm not an expert on ACS) you can perfrm similar mapping and response you get is a pure RADIUS one - i.e. easily understood by most networking equipment.

RADIUS give you more flexibility in terms of Authentication Authorization and Accounting for networking equpment.

For example (AFAIR) LDAP/AD will not do accounting nor can be used to perform NAC functions.

But for example both LDAP (Over SSL) and RADIUS (via mschap v2) can perform password expiry functions.

Marcin