6-39
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter6 Managing Policy Objects
Understanding AAA Server and Server Group Objects
LDAP Server Type The type of LDAP server used for AAA:
Auto-Detect—The ASA/PIX/FWSM device tries to determine the
server type automatically. This is the default.
Microsoft—The LDAP server is a Microsoft Active Directory
server.
Note You must configure LDAP over SSL to enable password
management with Microsoft Active Directory.
Sun—The LDAP server is a Sun Microsystems JAVA System
Directory Server.
OpenLDAP—The server is an Open LDAP server. You can use this
only with ASA/PIX 8.0+ devices.
Novell—The server is a Novell LDAP server. You can use this only
with ASA/PIX 8.0+ devices.
LDAP Attribute Map The LDAP attribute configuration to bind to the LDAP server. Enter the
name of an LDAP attribute map policy object or click Select to select
it from a list or to create a new object.
LDAP attribute maps take the attribute names that you define and map
them to Cisco-defined attributes. For more information, see Add and
Edit LDAP Attribute Map Dialog Boxes, page6-43.
Group Base DN (Microsoft LDAP AD servers only.) The base designated name (DN)
under which all user groups are defined. When the ASA contacts the
AD server for user group membership, the search starts at this DN. All
groups must reside under this DN in the LDAP directory hierarchy and
no group can reside outside of this path, or the group will not be found.
Specifying this location can decrease the time required to complete user
group searches.
The alphanumeric string is case-sensitive and can be up to 128
characters. Spaces are not permitted in the string, but other special
characters are allowed.
For example:
DN=cisco,DN=com
Tip If you do not specify the group base DN, the LDAP
Distinguished Name setting is used as the starting point for
group searches.
Group Search Timeout (Microsoft LDAP AD servers only.) The maximum time to wait for a
response from an Active Directory server queried for user group
information, in seconds. The default is 10 seconds, the range is 1 to 300
seconds.
IOS Tab
Secure Cipher The encryption method to be used.
Attribute Map (IOS) The name of the IOS attribute map the server employs.
Secure Trust Point The name of a trust point for certificates.
Table6-11 AAA Server Dialog Box—LDAP Settings (Continued)
Element Description