cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
457
Views
0
Helpful
0
Replies

ASDM access by active directory users

niLuxx
Level 1
Level 1

Dear community,

i would have a short question to you. We are using Cisco ASA 5508X in our office and doing homeoffice by using AnyConnect Client. We already configured user authentication against Active Directory server (Kerberos). Everything works fine, nevertheless we are facing some troubles adjusting access to management interfaces (ASDM, ssh connection to asa). The NAT rules and ACL were already configured, but unfortunately every person establishing a VPN connection now would have access to ASA management interfaces.

We already tried to enable "Identity options", but is it correct this cannot be used with Kerberos authentication? Is there another way to restrict access to ASDM for specific users connecting via VPN? 

Former we used LOCAL/AAA for authentication and assigned a static IP to specific usernames. Some IPs were permitted (other not) to call specific ports on ASA. That also did the job. Is there a similar way with AD-users and kerberos authentication?

 

Best regards

niLuxx

0 Replies 0