Solved

LDAP Auth with Pix

Posted on 2009-04-13
1
833 Views
Last Modified: 2012-05-06
I'm attempting to enable ldap authentication  for out pix firewall.  No problems there.

What I am having a problem with is limiting it to a certain OU in active directory.

I've followed these directions

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808d1a7c.shtml

Which allow the user in, but it also lets someone that isn't in the security group in too.

This article is closer to what I want to do.

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a008089149d.shtml

But, the way I'm attempting to get it to work is if your included in the memberOf grand access, if not then no access.

The second directions say to map this value

map-value msNPAllowDialin FALSE NOACCESS

But, I'm unsure what value mapped to

map-value memberOf (some ldap oU) NOACCESS

To make that value false.


0
Comment
Question by:kblackwel
1 Comment
 

Accepted Solution

by:
snoislelib earned 125 total points
ID: 24181017
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now