5-6
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 5 Identity Firewall
About the Identity Firewall
Figure 5-4
LAN -based Deployment
The following figure shows a WAN-based deployment to support a remote site. The Active Directory
server and the AD Agent are installed on the main site LAN. The clients are located at a remote site and
connect to the Identity Firewall components over a WAN.
Figure 5-5
WAN-based Deployment
The following figure also shows a WAN-based deployment to support a remote site. The Active
Directory server is installed on the main site LAN. However, the AD Agent is installed and accessed by
the clients at the remote site. The remote clients connect to the Active Directory servers at the main site
over a WAN.
Client
ASA
AD Servers
AD Agent
3
0400
3
LAN
NetBIOS Probe
mkg.example.com
10.1.1.2
WMI
LD
AP
RADIUS
Client
ASA
AD Servers
3
04008
Remote
S
ite
Enterpri
s
e Main
S
ite
NetBIOS Probe
Login/Authentication
mkg.example.com
10.1.1.2
WAN
AD Agent
WMI
RADIUS
LD
AP
Summary of Contents for ASA 5508-X
Page 11: ...P A R T 1 Access Control ...
Page 12: ......
Page 157: ...P A R T 2 Network Address Translation ...
Page 158: ......
Page 233: ...P A R T 3 Service Policies and Application Inspection ...
Page 234: ......
Page 379: ...P A R T 4 Connection Management and Threat Detection ...
Page 380: ......