06-13-2011 07:08 AM
If you are using LDAP attributes to map users to a specific group on the ASA is there a need for group lock if I want a user to connect to only one group? I am using the Cisco attribute Group-Policy to map an LDAP attribute = employee department i.e. sales, marketing, research, etc.
Regards,
Charles
Solved! Go to Solution.
06-13-2011 11:46 PM
No, if you already configure LDAP attribute map, then you do not need to configure group lock because LDAP attribute map will automatically map the user to the specific group policy that you have created through the mapping.
Hope that answers your question.
06-14-2011 12:14 AM
Hi,
I don't think there is any requirement for the enabling a group-lock on the tunnel-group if you are configuring a Ldap attribute map.
The user will get associated with the group-policy. so there is no need to enable a group lock.
Hope this helps.
Regards,
Anisha
P.S.:please mark this post as answered if you feel your query is resolved. Do rate helpful posts.
06-13-2011 11:46 PM
No, if you already configure LDAP attribute map, then you do not need to configure group lock because LDAP attribute map will automatically map the user to the specific group policy that you have created through the mapping.
Hope that answers your question.
06-14-2011 06:04 AM
Thank you Jennifer. Your response is greatly valued.
06-14-2011 12:14 AM
Hi,
I don't think there is any requirement for the enabling a group-lock on the tunnel-group if you are configuring a Ldap attribute map.
The user will get associated with the group-policy. so there is no need to enable a group lock.
Hope this helps.
Regards,
Anisha
P.S.:please mark this post as answered if you feel your query is resolved. Do rate helpful posts.
06-14-2011 06:42 AM
Thanks so much Anisha for the response. I have used RADIUS (ACS 4 and 5) to authenticate to Microsoft AD or RSA Token Servers in the past so I am new to LDAP. This customer doesn't have a RADIUS server.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide