1-10
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring the Identity Firewall
Task Flow for Configuring the Identity Firewall
See
Configuring Active Directory Agents, page 1-12
.
See also
Deployment Scenarios, page 1-4
for the ways in which you can deploy the AD Agents to meet
your environment requirements.
Step 3
Configure Identity Options.
See
Configuring Identity Options, page 1-13
.
Step 4
Configure Identity-based Security Policy.
After AD domain and AD-Agent are configured, you can create identity-based object groups and ACLs
for use in many features. See
Configuring Identity-Based Security Policy, page 1-18
Configuring the Active Directory Domain
Active Directory domain configuration on the ASA is required for the ASA to download Active
Directory groups and accept user identities from specific domains when receiving IP-user mapping from
the AD Agent.
Prerequisites
•
Active Directory server IP address
•
Distinguished Name for LDAP base dn
•
Distinguished Name and password for the Active Directory user that the Identity Firewall uses to
connect to the Active Directory domain controller
To configure the Active Directory domain, perform the following steps:
Command
Purpose
Step 1
hostname(config)#
aaa-server
server-tag
protocol
ldap
Example:
hostname(config)#
aaa-server adserver protocol ldap
Creates the AAA server group and configures AAA
server parameters for the Active Directory server.
Step 2
hostname(config-aaa-server-group)#
aaa-server
server-tag
[(
interface-name
)]
host
{
server-ip
|
name
} [
key
] [
timeout
seconds
]
Example:
hostname(config-aaa-server-group)#
aaa-server adserver
(mgmt) host 172.168.224.6
For the Active Directory server, configures the AAA
server as part of a AAA server group and the AAA
server parameters that are host-specific.
Step 3
hostname(
config-aaa-server-host
)#
ldap-base-dn
string
Example:
hostname(config-aaa-server-host)#
ldap-base-dn
DC=SAMPLE,DC=com
Specifies the location in the LDAP hierarchy where
the server should begin searching when it receives
an authorization request.
Specifying the
ldap-base-dn
command is optional.
If you do not specify this command, the ASA
retrieves the defaultNamingContext from Active
Directory and uses it as the base DN.
Step 4
hostname(config-aaa-server-host)#
ldap-scope
subtree
Specifies the extent of the search in the LDAP
hierarchy that the server should make when it
receives an authorization request.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......