07-02-2018 07:41 PM - edited 03-12-2019 05:25 AM
Does anyone know the correct syntax for enabling ldap-over-ssl for Active Directory (AD) authentication for remote access VPN on Cisco ASA?
I tried below and it didn't work:
aaa-server LDAP (inside) host x.x.x.x
ldap-over-ssl enable
server-port 636
07-03-2018 02:45 AM
Hi,
Those commands you have are a start, this link might be of some help with the other commands. You will need to ensure that the ASA has a trustpoint defined with the Root Certificate used by the AD domain controller to ensure trust.
HTH
07-10-2018 06:51 PM
Hi RJI,
Thank you for your post.
When it says this,
Install Necessary 3rd Party Vendor Certificates
If the internal network behind your ASA is using a different domain than your external network, be sure that you have the proper CA Certificates installed.
When it mean by using different domain than external? It is just for one customer's domain that we have.
And what do you mean by this:
Root Certificate used by the AD domain controller to ensure trust.
Is that the step required as mentioned above under the section " Install Necessary 3rd Party Vendor Certificates"?
Thank you!
07-14-2018 12:56 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide