1-4
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring the Identity Firewall
Information About the Identity Firewall
•
Supports a fully qualified domain name (FQDN) for the source and destination of a user identity
policy.
•
Supports the combination of 5-tuple policies with ID-based policies. The identity-based feature
works in tandem with existing 5-tuple solution.
•
Supports usage with IPS and Application Inspection policies.
•
Retrieves user identity information from remote access VPN, AnyConnect VPN, L2TP VPN and
cut-through proxy. All retrieved users are populated to all ASA devices connected to the AD Agent.
Scalability
•
Each AD Agent supports 100 ASA devices. Multiple ASA devices are able to communicate with a
single AD Agent to provide scalability in larger network deployments.
•
Supports 30 Active Directory servers provided the IP address is unique among all domains.
•
Each user identity in a domain can have up to 8 IP addresses.
•
Supports up to 64,000 user identity-IP address mappings in active ASA policies for ASA 5500
Series models. This limit controls the maximum users who have policies applied. The total users are
the aggregated users configured on all different contexts.
•
Supports up to 1024 user identity-IP address mappings in active ASA policies for the ASA 5505.
•
Supports up to 256 user groups in active ASA policies.
•
A single rule can contain one or more user groups or users.
•
Supports multiple domains.
Availability
•
The ASA retrieves group information from Active Directory and falls back to web authentication
for IP addresses that the AD Agent cannot map a source IP address to a user identity.
•
The AD Agent continues to function when any of the Active Directory servers or the ASA are not
responding.
•
Supports configuring a primary AD Agent and a secondary AD Agent on the ASA. If the primary
AD Agent stops responding, the ASA can switch to the secondary AD Agent.
•
If the AD Agent is unavailable, the ASA can fall back to existing identity sources such as cut through
proxy and VPN authentication.
•
The AD Agent runs a watchdog process that automatically restarts its services when they are down.
•
Allows a distributed IP address/user mapping database among ASA devices.
Deployment Scenarios
You can deploy the components of the Identity Firewall in the following ways depending on your
environmental requirement.
, you can deploy the components of the Identity Firewall to allow for redundancy.
Scenario 1 shows a simple installation without component redundancy.
Scenario 2 also shows a simple installation without redundancy. However, in that deployment scenario,
the Active Directory server and AD Agent are co-located on one Windows server.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......