35-17
Cisco ASA 5500 Series Configuration Guide using the CLI
Chapter35 Configuring AAA Servers and the Local Database
Configuring AAA
To set up VPN user authorization using LDAP, perform the following steps.
Detailed Steps
Examples
While there are other authorization-related commands and options available for specific requirements,
the following example shows commands for enabling user authorization with LDAP. The example then
creates an IPsec remote access tunnel group named remote-1, and assigns that new tunnel group to the
previously created ldap_dir_1 AAA server group for authorization:
hostname(config)# tunnel-group remote-1 type ipsec-ra
hostname(config)# tunnel-group remote-1 general-attributes
hostname(config-general)# authorization-server-group ldap_dir_1
hostname(config-general)#
After you complete this configuration work, you can then configure additional LDAP authorization
parameters such as a directory password, a starting point for searching a directory, and the scope of a
directory search by entering the following commands:
hostname(config)# aaa-server ldap_dir_1 protocol ldap
hostname(config-aaa-server-group)# aaa-server ldap_dir_1 host 10.1.1.4
hostname(config-aaa-server-host)# ldap-login-dn obscurepassword
hostname(config-aaa-server-host)# ldap-base-dn starthere
hostname(config-aaa-server-host)# ldap-scope subtree
hostname(config-aaa-server-host)#
Command Purpose
Step1 aaa-server server_group protocol {kerberos | ldap | nt |
radius | sdi | tacacs+}
Example:
hostname(config)# aaa-server servergroup1 protocol
ldap
hostname(config-aaa-server-group)
Creates a AAA server group.
Step2 tunnel-group groupname
Example:
hostname(config)# tunnel-group remotegrp
Creates an IPsec remote access tunnel group named
remotegrp.
Step3 tunnel-group groupname general-attributes
Example:
hostname(config)# tunnel-group remotegrp
general-attributes
Associates the server group and the tunnel group.
Step4 authorization-server-group group-tag
Example:
hostname(config-general)# authorization-server-group
ldap_dir_1
Assigns a new tunnel group to a previously created
AAA server group for authorization.