cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3338
Views
5
Helpful
15
Replies

ASA LDAP Attribute-map issue : VPN users can connecet to any group policy

sam cook
Spotlight
Spotlight

Hi,

 

I have an issue with VPN users authentication.

 

The problem is : if the user is member of a valid group policy , he can connect to any group policy.

 

here are my config : cisco ASA 9.13

 

ldap attribute-map Class
map-name memberOf Group-Policy
map-value memberOf CN=*******,CN=Users,DC=in,DC=ac-arcueil,DC=fr ***********
map-value memberOf CN=********,CN=Users,OU=stbu,DC=cisco,DC=com **************P

 

 

 

 

in "debug ldap 255" I can see : 



 

 

Any idea please ?

15 Replies 15

Hi @harmesh88 ,

 

thank you , but as you can see in previous conversation , I already did that and I still get users able to connect to other tunnel groups.