Cisco ASA 5505 Configuration Manual page 662

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Configuring AAA Server Groups
Field
Login DN
Login Password
LDAP Attribute Map
SASL MD5 authentication
check box
SASL Kerberos
authentication
Kerberos Server Group
Cisco ASA 5500 Series Configuration Guide using ASDM
31-16
Chapter 31
Description
The adaptive security appliance uses the Login Distinguished Name
(DN) and Login Password to establish trust (bind) with an LDAP server.
The Login DN represents a user record in the LDAP server that the
administrator uses for binding.
When binding, the adaptive security appliance authenticates to the
server using the Login DN and the Login password. When performing a
Microsoft Active Directory read-only operation (such as authentication,
authorization, or group-search), the adaptive security appliance can bind
with a Login DN with fewer privileges. For example, the Login DN can
be a user whose AD "Member Of" designation is part of Domain Users.
For VPN password management operations, the Login DN needs
elevated privileges and must be part of the Account Operators AD
group.
The following is an example of a Login DN:
cn=Binduser1,ou=Admins,ou=Users,dc=company_A,dc=com
The adaptive security appliance supports:
Simple LDAP authentication with an unencrypted password on port
389
Secure LDAP (LDAP-S) on port 636
Simple Authentication and Security Layer (SASL) MD5
SASL Kerberos
The adaptive security appliance does not support anonymous
authentication.
The password for the Login DN user account. The characters you type
are replaced with asterisks.
The LDAP attribute maps that you can apply to LDAP server. Used to
map Cisco attribute names to user-defined attribute names and values.
See the
"Configuring LDAP Attribute Maps" section on page
When checked, the MD5 mechanism of the SASL authenticates
communications between the adaptive security appliance and the LDAP
server.
When checked, the Kerberos mechanism of the SASL secures
authentication communications between the adaptive security appliance
and the LDAP server.
The Kerberos server or server group used for authentication. The
Kerberos Server group option is disabled by default and is enabled only
when SASL Kerberos authentication is chosen.
Configuring AAA Servers and the Local Database
31-22.
OL-20339-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents