name 172.18.1.0 RATHBONE_VPN_POOL
name 172.16.0.0 LAN40
name 10.10.10.0 VLAN60_Internet
name 172.16.1.5 DC1
!
!
object network Private_Lan
subnet 172.16.0.0 255.255.0.0
!
object-group network obj-local_ipsec_tunnel
network-object LAN40 255.255.0.0
!
object-group network obj-remote_ipsec_tunnel
network-object RATHBONE_VPN_POOL 255.255.255.0
!
access-list FIREWALL_GW_cryptomap_1 standard permit 172.16.0.0 255.255.0.0
!
!
ip local pool RATHBONE_VPN_POOL 172.18.1.1-172.18.1.254 mask 255.255.255.0
!
nat (FIREWALL_FW,FIREWALL_GW) source static obj-local_ipsec_tunnel
obj-local_ipsec_tunnel destination static obj-remote_ipsec_tunnel obj-remote_ipsec_tunnel
!
!
object network Private_Lan
nat (FIREWALL_FW,FIREWALL_GW) dynamic interface
!
route FIREWALL_GW 0.0.0.0 0.0.0.0 192.168.2.2 1
route FIREWALL_GW VLAN60_Internet 255.255.255.0 192.168.2.1 1
route FIREWALL_FW LAN40 255.255.0.0 192.168.1.1 1
route FIREWALL_FW RATHBONE_VPN_POOL 255.255.255.0 192.168.1.1 1
!
!
ldap attribute-map RATHBONEMAP
map-name memberOf IETF-Radius-Class
map-value memberOf CN=RemoteVPN,OU=RemoteUsers,DC=rathboneuk,DC=local AllowRemoteUsers
dynamic-access-policy-record DfltAccessPolicy
!
aaa-server Rathbone_LDAP protocol ldap
!
aaa-server Rathbone_LDAP (FIREWALL_FW) host DC1
server-port 389
ldap-base-dn dc=rathboneuk,dc=local
ldap-group-base-dn dc=rathboneuk,dc=local
ldap-scope subtree
ldap-naming-attribute sAMAccountname
ldap-login-password globalwave
ldap-login-dn CN=Administrator,CN=Users,DC=rathboneuk,DC=local
server-type microsoft
ldap-attribute-map RATHBONEMAP
!
******************************************************************
As we continue with the sub commands, we provide a username and password for the
ASA to use in order to log into AD and make sure the user exists.
I usually let the Windows admin dictate the name.
In this example, the username is Administrator. In order to have a successful
implementation, you can use the following command to test the LDAP authentication:
“test aaa-server authentication Rathbone_LDAP host 10.1.1.2 username
Administrator password globalwave“.
If the test fails, I recommend you stop and figure out the AD problems first.
use this command on a domain controller to find the full path of the ASAuser account:
dsquery user -samid ASAUser
Your login DN has to contain the complete location of the user ID you are using.
For example CN=ASAUser,OU=ServiceAccounts,DC=cisco,DC=com
******************************************************************
!
crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
!
crypto dynamic-map Rathbone_Vpn 1 set ikev1 transform-set ESP-3DES-MD5
crypto dynamic-map Rathbone_Vpn 1 set security-association lifetime seconds 86400
crypto dynamic-map Rathbone_Vpn 1 set security-association lifetime kilobytes 9908000
crypto dynamic-map Rathbone_Vpn 1 set reverse-route
!
crypto map FIREWALL_GW 10 ipsec-isakmp dynamic Rathbone_Vpn
!
no crypto isakmp nat-traversal
sysopt connection permit-ipsec
!
crypto ikev1 enable FIREWALL_GW
!
crypto ikev1 policy 10
authentication pre-share
encryption 3des
hash md5
group 2
lifetime 86400
!
!
group-policy AllowRemoteUsers internal
group-policy AllowRemoteUsers attributes
banner value Welcome you are logged in with Support rights and full access
dns-server value 172.16.1.5 172.16.1.14
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value FIREWALL_GW_cryptomap_1
default-domain value rathboneuk.local
nem enable
!
group-policy NOACCESS internal
group-policy NOACCESS attributes
vpn-simultaneous-logins 0
vpn-tunnel-protocol ikev1 l2tp-ipsec
!
tunnel-group RATHBONEVPN type remote-access
tunnel-group RATHBONEVPN general-attributes
address-pool RATHBONE_VPN_POOL
authentication-server-group Rathbone_LDAP
default-group-policy NOACCESS
password-management password-expire-in-days 30
authorization-required
!
tunnel-group RATHBONEVPN ipsec-attributes
ikev1 pre-shared-key rathbone
isakmp keepalive threshold 20 retry 10
!
!
To troubleshoot any issues enable the following debugs.
debug aaa authentication enabled at level 1
debug aaa authorization enabled at level 1
debug aaa common enabled at level 15
debug ldap enabled at level 15
!
!
Remove Configuration :
no nat (FIREWALL_FW,FIREWALL_GW) source static obj-local_ipsec_tunnel obj-local_ipsec_tunnel destination static obj-remote_ipsec_tunnel obj-remote_ipsec_tunnel
!
no access-list FIREWALL_GW_cryptomap_1 standard permit 172.16.0.0 255.255.0.0
!
no ip local pool RATHBONE_VPN_POOL 172.18.1.1-172.18.1.254 mask 255.255.255.0
!
no name 172.18.1.0 RATHBONE_VPN_POOL
no name 172.16.0.0 LAN40
no name 10.10.10.0 VLAN60_Internet
no name 172.16.1.5 DC1
!
!
object network Private_Lan
no nat (FIREWALL_FW,FIREWALL_GW) dynamic interface
exit
no object network Private_Lan
!
no route FIREWALL_GW 0.0.0.0 0.0.0.0 192.168.2.2 1
no route FIREWALL_GW VLAN60_Internet 255.255.255.0 192.168.2.1 1
no route FIREWALL_FW LAN40 255.255.0.0 192.168.1.1 1
no route FIREWALL_FW RATHBONE_VPN_POOL 255.255.255.0 192.168.1.1 1 !
!
no ldap attribute-map RATHBONEMAP
!
no aaa-server Rathbone_LDAP protocol ldap
no aaa-server Rathbone_LDAP (FIREWALL_FW) host DC1
!
no crypto map FIREWALL_GW 10 ipsec-isakmp dynamic Rathbone_Vpn
no crypto dynamic-map Rathbone_Vpn 1
no crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
!
no crypto isakmp nat-traversal
no sysopt connection permit-ipsec
!
no crypto ikev1 enable FIREWALL_GW
!
no crypto ikev1 policy 10
!
no group-policy AllowRemoteUsers internal
no group-policy AllowRemoteUsers attributes
!
no group-policy NOACCESS internal
no group-policy NOACCESS attributes
!
clear configure tunnel-group RATHBONEVPN
Comments
(There are currently no comments for this post.)