1. Topology Map:
Reference: http://bbs.51cto.com/thread-728599-1-1.html
2.ASA Configuration steps:
A. Adding an LDAP authentication type of Aaa-server
Aaa-server yuntian.com Protocol LDAP
Max-failed-attempts 2
Aaa-server yuntian.com (inside) host 100.1.1.100
Ldap-base-dn cn=users,dc=yuntian,dc=com
Ldap-group-base-dn dc=yuntian,dc=com
Ldap-scope subtree
Ldap-login-password * * * *
Ldap-login-dn cn=xllldap,cn=users,dc=yuntian,dc=com
Server-type Microsoft
B. Set host IP to allow Telnet:
Telnet 100.1.1.0 255.255.255.0 inside
C. Conduct AAA test:
ciscoasa# Test Aaa-server authentication yuntian.com username xllldap password 1234qwer,
Server IP address or name:100.1.1.100
Info:attempting authentication test to IP address <100.1.1.100> (timeout:12 seconds)
Info:authentication Successful
See more highlights of this column: http://www.bianceng.cnhttp://www.bianceng.cn/Network/Firewall/
D. Add accounts and test logins in a domain-controlled ad:
User Access Verification
Username:xll
Password: ********
Username:administrator
Password: *********
Type help or '? ' for a list of available C
Ciscoasa> en
Password:
ciscoasa#
This article comes from "Httpyuntianjxxll.spac" blog, please be sure to keep this source http://333234.blog.51cto.com/323234/931998