1-4
Cisco ASA Series CLI Configuration Guide
Appendix 1 Configuring an External Server for Authorization and Authentication
Configuring an External LDAP Server
•
Search Scope defines the extent of the search in the LDAP hierarchy. The search proceeds this many
levels in the hierarchy below the LDAP Base DN. You can choose to have the server search only the
level immediately below it, or it can search the entire subtree. A single level search is quicker, but
a subtree search is more extensive.
•
Naming Attribute(s) defines the RDN that uniquely identifies an entry in the LDAP server. Common
naming attributes can include cn (Common Name), sAMAccountName, and userPrincipalName.
shows a sample LDAP hierarchy for Example Corporation. Given this hierarchy, you could
define your search in different ways.
shows two sample search configurations.
In the first example configuration, when Employee1 establishes the IPsec tunnel with LDAP
authorization required, the ASA sends a search request to the LDAP server, indicating it should search
for Employee1 in the Engineering group. This search is quick.
In the second example configuration, the ASA sends a search request indicating that the server should
search for Employee1 within Example Corporation. This search takes longer.
Binding the ASA to the LDAP Server
Some LDAP servers (including the Microsoft Active Directory server) require the ASA to establish a
handshake via authenticated binding before they accept requests for any other LDAP operations. The
ASA uses the Login Distinguished Name (DN) and Login Password to establish a trust relationship
(bind) with an LDAP server before a user can search. The Login DN represents a user record in the LDAP
server that the administrator uses for binding.
When binding, the ASA authenticates to the server using the Login DN and the Login Password. When
performing a Microsoft Active Directory read-only operation (such as for authentication, authorization,
or group search), the ASA can bind with a Login DN with fewer privileges. For example, the Login DN
can be a user whose AD “Member Of” designation is part of Domain Users. For VPN password
management write operations, the Login DN needs elevated privileges and must be part of the Account
Operators AD group. Microsoft Active Directory group search (also called “MemberOf retrieval”) was
added in ASA Version 8.0.4.
An example of a Login DN includes the following entries:
cn=Binduser1,ou=Admins,ou=Users,dc=company_A,dc=com
See your LDAP Administrator guide for specific Login DN requirements for read and write operations.
The ASA supports the following features:
•
Simple LDAP authentication with an unencrypted password using the default port 389 . You can also
use other ports instead of the default port.
•
Secure LDAP (LDAP-S) using the default port 636. You can also use other ports instead of the
default port.
•
Simple Authentication and Security Layer (SASL) MD5
•
SASL Kerberos
The ASA does not support anonymous authentication.
Table 1-1
Example Search Configurations
No
.
LDAP Base DN
Search
Scope
Naming
Attribute
Result
1
group= Engineering,ou=People,dc=ExampleCorporation, dc=com One Level
cn=Employee1 Quicker search
2
dc=ExampleCorporation,dc=com
Subtree
cn=Employee1 Longer search
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......