70-17
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter70 Configuring Dynamic Access Policies
DAP and Authentication, Authorization, and Accounting Services
Figure70-5 Retrieve AD Groups Dialog Box
You can query an Active Directory server for available AD groups in this pane. This feature applies only
to Active Directory servers using LDAP. Use the group information to specify dynamic access policy
AAA selection criteria.
You can change the level in the Active Directory hierarchy where the search begins by changing the
Group Base DN in the Edit AAA Server pane. You can also change the time that the ASA waits for a
response from the server in the window. To configure these features, choose
Configuration > Remote Access VPN > AAA/Local Users > AAA Server Groups > Edit AAA Server.
Note If the Active Directory server has a large number of groups, the list of AD groups retrieved may be
truncated based on limitations of the amount of data the server can fit into a response packet. To avoid
this problem, use the filter feature to reduce the number of groups reported by the server.
Fields
AD Server Group—The name of the AAA server group to retrieve AD groups.
Filter By—Specify a group or the partial name of a group to reduce the groups displayed.
Group Name—A list of AD groups retrieved from the server.
AAA Attribute Definitions
Table70-2 defines the AAA selection attribute names that are available for DAP use. The Attribute
Name field shows you how to enter each attribute name in a Lua logical expression, which you might do
in the Advanced section of the Add/Edit Dynamic Access Policy pane.
Table70-2 AAA Selection Attributes for DAP Use
Attribute
Type Attribute Name Source Value
Max String
Length Description
Cisco aaa.cisco.grouppolicy AAA string 64 Group policy name on the ASA or sent from
a Radius/LDAP server as the IETF-CLass
(25) attribute