10-05-2012 01:16 PM
Hello All,
I am planning to implement SSL-VPN (AnyConnect) on an ASR 1002 rputer running IOS-XE Software Version 15.1(3)S2.
I need to use LDAP for user authentication, and need to understand what are RADIUS/TACACS requirements to use LDAP.
Do I need to use Cisco ACS or can I use something like Microsoft IAS or Free Raduis?
Any helo will be greatly appreciated.
Thank you
Dmitry.
Solved! Go to Solution.
10-05-2012 03:35 PM
Yes, you can use either use LDAP, Radius or Tacacs protocols to authenticate the SSL VPN users.
You can use any authentication server (doesn't need to be Cisco ACS), as long as they supports either of the 3 authentication protocols (ldap, radius or tacacs).
Hope that answers your question.
10-06-2012 07:32 PM
Here is more information on FlexVPN:
https://supportforums.cisco.com/community/netpro/security/vpn/blog/2012/03/19/flexvpn-at-a-glance
https://supportforums.cisco.com/docs/DOC-23967
https://supportforums.cisco.com/docs/DOC-26834
FlexVPN in short is IKEv2
10-05-2012 03:35 PM
Yes, you can use either use LDAP, Radius or Tacacs protocols to authenticate the SSL VPN users.
You can use any authentication server (doesn't need to be Cisco ACS), as long as they supports either of the 3 authentication protocols (ldap, radius or tacacs).
Hope that answers your question.
10-05-2012 04:16 PM
Thank you Jennifer.
I came across the below configuration guide about SSL VPN on IOS and it states that LDAP is not supported on IOS SSL VPN's. Just wndering if this is in fact true or newer IOS version support LDAP.
Features Not Supported on the Cisco IOS SSL VPN
The following features are not supported on the Cisco IOS SSL VPN:
• Lightweight Directory Access Protocol (LDAP) Support
Dmitry.
10-06-2012 01:12 AM
Actually, SSL VPN (AnyConnect) is not supported on ASR platform, only on IOS, not on IOS-XE.
10-06-2012 08:31 AM
I found some information on Flex VPN on the IOS-XE platfrom, how is that differenct from IPSEC VPN?
10-06-2012 07:32 PM
Here is more information on FlexVPN:
https://supportforums.cisco.com/community/netpro/security/vpn/blog/2012/03/19/flexvpn-at-a-glance
https://supportforums.cisco.com/docs/DOC-23967
https://supportforums.cisco.com/docs/DOC-26834
FlexVPN in short is IKEv2
10-07-2012 03:43 PM
Thank you very much for the information Jennifer!
Dmitry.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide