cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
389
Views
0
Helpful
1
Replies

Can I use Radius to get AD group info

rhienwei2010
Level 1
Level 1

I am using LDAP on my ASA and DAP, to assign VPN users from different AD group with different network access.  But now my LDAP server is about to be decommissioned, and I only can get a Radius server in replacment.  So, can I use Radius like I used LDAP 'memberOf' attribute to give my VPN users different access based on their WINs AD group?

Thanks a lot.

1 Reply 1

Marcin Latosiewicz
Cisco Employee
Cisco Employee

RADIUS will rely on class attribute to pick a gorup policy.

Supported RADIUS attributes on ASA:

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ref_extserver.html

The mechanics within to map groups to anything on AD is not something I'm aware.

Incidentally it's first time I hear about AD without possibility to use LDAP (or LDAPS).