I am trying to setup authentication/authorizati
on for SSLVPN users on ASA firewall.
I know how to setup authentication/authorizati
on server groups and tie that into group-policies or 'tunnel-groups'.
This is what I am looking to do in terms of user experience:
When users try to log in to remote access SSLVPN gateway (ASA firewall) they should 'first' use Active directory credentials (user/pass) and then if that is successful they should get prompted for the SecureID pin (users will have hardware tokens).
All the docs I have gone thru on cisco shows how to setup authentication first using RSA SecureID (SDI or RADIUS) and then configure 'Authorization' using LDAP. Using this method I would get the remote users to first authenticate through RSA SecureID Pin and then they would provide for the LDAP credentials.
Is there a way to authenticate using LDAP first and then provide the second factor using RSA???
Thanks in advance for your answers.
Start Free Trial