cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1356
Views
0
Helpful
4
Replies

LDAP Attribute Mapping

cclem
Level 1
Level 1

If you are using LDAP attributes to map users to a specific group on the ASA is there a need for group lock if I want a user to connect to only one group? I am using the Cisco attribute Group-Policy to map an LDAP attribute = employee department i.e. sales, marketing, research, etc. 

Regards,

Charles

2 Accepted Solutions

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee

No, if you already configure LDAP attribute map, then you do not need to configure group lock because LDAP attribute map will automatically map the user to the specific group policy that you have created through the mapping.

Hope that answers your question.

View solution in original post

andamani
Cisco Employee
Cisco Employee

Hi,

I don't think there is any requirement for the enabling a group-lock on the tunnel-group if you are configuring a Ldap attribute map.

The user will get associated with the group-policy. so there is no need to enable a group lock.

Hope this helps.

Regards,

Anisha

P.S.:please mark this post as answered if you feel your query is resolved. Do rate helpful posts.

View solution in original post

4 Replies 4

Jennifer Halim
Cisco Employee
Cisco Employee

No, if you already configure LDAP attribute map, then you do not need to configure group lock because LDAP attribute map will automatically map the user to the specific group policy that you have created through the mapping.

Hope that answers your question.

Thank you Jennifer. Your response is greatly valued.

andamani
Cisco Employee
Cisco Employee

Hi,

I don't think there is any requirement for the enabling a group-lock on the tunnel-group if you are configuring a Ldap attribute map.

The user will get associated with the group-policy. so there is no need to enable a group lock.

Hope this helps.

Regards,

Anisha

P.S.:please mark this post as answered if you feel your query is resolved. Do rate helpful posts.

Thanks so much Anisha for the response. I have used RADIUS (ACS 4 and 5) to authenticate to Microsoft AD or RSA Token Servers in the past so I am new to LDAP.  This customer doesn't have a RADIUS server.