Avatar of François Darveau
François DarveauFlag for Canada asked on

NX-OS LDAP authorization role assignation

Hi, I need  to configure LDAP on Nexus 9300, all users who will log in needs to be network-admin. I can authenticate but I struggle with the authorization part.

I tough of to ways doing it


1- Add members to Active directory Group, use a ldap-search-map to allow users to login,

SEARCH MAP  map10:
    User Profile :
        BaseDN: MY_OU,DC=TEST,DC=DC,DC=NET
        Attribute Name: memberOf
       Search Filter: (&(name=$userid)(memberOf=CN=My_Group,DC=TEST,DC=DC,DC=NET))

Open in new window

With map10, only the users in My_Group can log in, They get the default role : network-operator and I did not find a way to change the default-role


2- Add the role in a Active directory attribute Extensionattribute10 in combination with the AD group (shell:roles=network-admin))

SEARCH MAP  map11:
      User Profile :
        BaseDN: MY_OU,DC=TEST,DC=DC,DC=NET
        Attribute Name: Extensionattribute10
       Search Filter: (&(name=$userid)(memberOf=CN=My_Group,DC=TEST,DC=DC,DC=NET))

Open in new window

map11 is not working


How Can I control who is able to connect and assign a the role network-admin?

* Cisco NexusActive Directory* NXOSCisco

Avatar of undefined
Last Comment
François Darveau

8/22/2022 - Mon
Craig Beck

Using the memberOf attribute won't work. You need to map a shell-profile to the user using the description attribute, or some other free-text attribute.

Have a look at this great writeup showing how to do it...
http://ccierants.blogspot.com/2013/07/ccie-dc-sort-of-ldap-authentication-to.html

ASKER CERTIFIED SOLUTION
François Darveau

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck