cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2051
Views
10
Helpful
4
Replies

ASA DAP using LDAP member of attribute

balmain99
Level 1
Level 1

Hello,

is it compulsory to create an LDAP attribute map in order to use a DAP entry with the LDAP member of check ? My attempted DAP entry does not not seem to take this into account at all.

 

1 Accepted Solution

Accepted Solutions

Yes you need to create attribute map for ASA to be able to map LDAP
attributes to ASA attributes. This mapping doesn't exist by default in ASA
and LDAP attribute maps are used to leverage this.

View solution in original post

4 Replies 4

Yes you need to create attribute map for ASA to be able to map LDAP
attributes to ASA attributes. This mapping doesn't exist by default in ASA
and LDAP attribute maps are used to leverage this.

Rahul Govindan
VIP Alumni
VIP Alumni
I do not think so. LDAP attributes are returned without ldap attribute maps configured. Only if you need to map "member-of" to a group-policy (or any other ASA attribute) do you need the LDAP attribute map.

DAP itself cannot assign a group policy to a user, but you can use LDAP member-of as a AAA condition without creating an LDAP attribute map.

I will try to clarify by attaching a snip. This is what I am trying to enable.

 

 

You are basically adding ldap member-of as a AAA condition on DAP. You don't need an LDAP attribute map to do this.