5-2
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 5 Identity Firewall
About the Identity Firewall
Architecture for Identity Firewall Deployments
The Identity Firewall integrates with Window Active Directory in conjunction with an external Active
Directory (AD) Agent that provides the actual identity mapping.
The identity firewall consists of three components:
•
ASA
•
Microsoft Active Directory
Although Active Directory is part of the Identity Firewall on the ASA, Active Directory
administrators manage it. The reliability and accuracy of the data depends on data in Active
Directory.
Supported versions include Windows Server 2003, Windows Server 2008, and Windows Server
2008 R2 servers.
•
Active Directory (AD) Agent
The AD Agent runs on a Windows server. Supported Windows servers include Windows 2003,
Windows 2008, and Windows 2008 R2.
Note
Windows 2003 R2 is not supported for the AD Agent server.
The following figure show the components of the Identity Firewall. The succeeding table describes the
roles of these components and how they communicate with one another.
Summary of Contents for ASA 5508-X
Page 11: ...P A R T 1 Access Control ...
Page 12: ......
Page 157: ...P A R T 2 Network Address Translation ...
Page 158: ......
Page 233: ...P A R T 3 Service Policies and Application Inspection ...
Page 234: ......
Page 379: ...P A R T 4 Connection Management and Threat Detection ...
Page 380: ......