cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2148
Views
5
Helpful
15
Replies

ASA LDAP Attribute-map issue : VPN users can connecet to any group policy

sam cook
Spotlight
Spotlight

Hi,

 

I have an issue with VPN users authentication.

 

The problem is : if the user is member of a valid group policy , he can connect to any group policy.

 

here are my config : cisco ASA 9.13

 

ldap attribute-map Class
map-name memberOf Group-Policy
map-value memberOf CN=*******,CN=Users,DC=in,DC=ac-arcueil,DC=fr ***********
map-value memberOf CN=********,CN=Users,OU=stbu,DC=cisco,DC=com **************P

 

 

 

 

in "debug ldap 255" I can see : 



 

 

Any idea please ?

15 Replies 15

Hi @harmesh88 ,

 

thank you , but as you can see in previous conversation , I already did that and I still get users able to connect to other tunnel groups.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: