Networking-Blog

My WordPress Blog

Cisco ASA QoS for VoIP Traffic

In our example below, we present a usual scenario in which we have two (or more)
sites communicating through a Lan-to-Lan IPSEC VPN via the Internet.

Between the sites we can have both data and VoIP traffic communication.
Although we can not enforce real QoS through the Internet, at least we can ensure
voice traffic prioritization on the firewall interface.

From the diagram above we assume that we have already configured the IPSEC VPN
and is working properly (i.e both subnets 192.168.1.0/24 and 192.168.2.0/24 can
communicate via the tunnel
).

The example configuration below is for the ASA-1 firewall and should be applied accordingly
to ASA-2 for better QoS performance.

!

Enable a priority queue on the outside interface

ASA-1(config)# priority-queue outside
ASA-1(config-priority-queue)# exit

!

Select VoIP traffic for prioritization

access-list VoIP-Traffic-OUT extended permit tcp
192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0 eq h323
!
access-list VoIP-Traffic-OUT extended permit tcp
192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0 eq sip
!
access-list VoIP-Traffic-OUT extended permit tcp
192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0 eq 2000
!
access-list VoIP-Traffic-IN extended permit tcp
192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0 eq h323
!
access-list VoIP-Traffic-IN extended permit tcp
192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0 eq sip
!
access-list VoIP-Traffic-IN extended permit tcp
192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0 eq 2000
!

Match the ACL and traffic with Expedited Forwarding (EF)

class-map Voice-OUT
match dscp ef
match access-list VoIP-Traffic-OUT
exit
!
class-map Voice-IN
match dscp ef
match access-list VoIP-Traffic-IN
exit

!

Configure the actual policy that will be applied to the interface

policy-map VoicePolicy
class Voice-OUT
priority
exit

class Voice-IN
priority
exit

!

Apply the policy to the outside interface

service-policy VoicePolicy interface outside

In your example above. Please indicate ASA-2 outside interface with a priority queue
applied to it’s outside interface matching traffic going from 192.168.2.0/24 to 192.168.1.0/24.

ASA 8.0 ENABLE SNMP

snmp-server host outside 80.74.17.9 poll community netmangler version 2c
snmp-server location London
snmp-server contact Waveworks
snmp-server community netmangler
snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart

Configuration Example for SNMP Versions 1 and 2c

The following example shows how the ASA can receive SNMP requests from
host 192.0.2.5 on the inside interface, but does not send any SNMP syslog requests
to any host:

snmp-server host 192.0.2.5
snmp-server location building 42
snmp-server contact EmployeeA

snmp-server community ohwhatakeyisthee

Configuration Example for SNMP Version 3

The following example show how the ASA can receive SNMP requests using the
SNMP Version 3 security model, which requires that the configuration follow
this specific order: group, followed by user, followed by host:

snmp-server group v3 vpn-group priv
snmp-server user admin vpn group v3 auth sha letmein priv 3des cisco123
snmp-server host mgmt 10.0.0.1 version 3 priv admin


Provides 3DES or AES encryption and support for SNMP Version 3, the most secure
form of the supported security models. This version allows you to configure users,
groups, and hosts, as well as authentication characteristics by using the USM.
In addition, this version allows access control to the agent and MIB objects, and
includes additional MIB support.

To obtain a list of the supported SNMP MIBs for a specified ASA,
enter the following command:

hostname(config)# show snmp-server oidlist

The following commands were introduced:

show snmp-server engineid
show snmp-server group
show snmp-server user
snmp-server group
snmp-server user

CISCO ASA SYSLOG

Use the logging list command in order to capture the syslog for LAN-to-LAN and Remote access
IPsecVPN messages alone.

This example captures all VPN (IKE and IPsec) class system log messages with debugging level or higher.

Example:

hostname(config)#logging enable
hostname(config)#logging timestamp
hostname(config)#logging list my-list level debugging class vpn
hostname(config)#logging trap my-list
hostname(config)#logging host inside 192.168.1.1


Troubleshoot

If you do not receive the syslog 304001 messages, then make sure that the
inspect http command is enabled on the ASA.

If you want to deny a specific syslog message to be sent to syslog server,
then you must use the command as shown.

hostname(config)#no logging message <syslog_id>

Usage Guidelines

If you are using TCP as the logging transport protocol for sending messages to a
syslog server, the security appliance denies new network access sessions as a security
measure if the security appliance is unable to reach the syslog server.

You can use the logging permit-hostdown command to remove this restriction.

Examples

The following example makes the status of TCP-based syslog servers irrelevant to whether
the security appliance permits new sessions. When the logging permit-hostdown command
includes in its output the show running-config logging command, the status of TCP-based
syslog
servers is irrelevant to new network access sessions
.

hostname(config)# logging permit-hostdown
hostname(config)# show running-config logging
logging enable
logging trap errors
logging host infrastructure 10.1.2.3 6/1470
logging permit-hostdown

Cisco ASA IPSEC VPN Remove

no access-list Colo_cryptomap_4180 extended permit ip object-group MPLS_Sites 10.2.223.0 255.255.255.0
!
no access-list Colo_cryptomap_4180 extended permit ip object-group Wates_Remote_PrivateIP_Range 10.2.223.0 255.255.255.0
!
no access-list Colo_cryptomap_4180 extended permit ip object-group Cable_Wireless_Range 10.2.223.0 255.255.255.0
!
object-group network Wates_Remote_PrivateIP_Range
no network-object 10.2.223.0 255.255.255.0
exit
no name 10.2.223.0 wit1399
clear configure crypto map Colo_map 4180
clear configure tunnel-group 80.74.21.50

ASA VPN LDAP Authentication + Group Membership

The logic here will allow Remote VPN users to connect so long as they are a member of
either the SupportStaff or Managers group within the Microsoft active directory.
Members of the Managers group within the AD will have more restricted access that
members of SupportStaff.

If an AD user isn’t a member of one of these groups,they will be denied access.

The following key aspects of configuration need to be completed;

  • aaa-server
  • ldap attribute-map
  • access-lists
  • ip address pools
  • webvpn parameters
  • group-policy
  • tunnel-group

Configure Your AAA server details. The user “ldap_user” is a standard user within the
Microsoft AD, ideally this users password (ldap_users_password) should be set to never expire.

aaa-server Company1-LDAP protocol ldap
aaa-server Company1-LDAP (inside) host 10.1.1.2
ldap-base-dn dc=company1,dc=co,dc=uk
server-port 389
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password globalwave
ldap-login-dn CN=Administrator,CN=Users,DC=company1,DC=co,DC=uk
server-type microsoft
ldap-attribute-map
Company1-Map

!

Define your ldap attribute map. This will tell the Cisco ASA which locally configured
group policy to apply depending on the group membership status, within the Microsoft AD
of the user connecting via the SSL VPN.


ldap attribute-map Company1-Map
map-name memberOf IETF-Radius-Class
map-value memberOf “CN=SupportStaff,OU=User Accounts,DC=1stquote,DC=co,DC=uk”
ALLOWSupportAccess
map-value memberOf “CN=Managers,OU=User Accounts,DC=1stquote,DC=co,DC=uk”
ALLOWManagerAccess

As we continue with the sub commands, we provide a username and password for the
ASA to use in order to log into AD and make sure the user exists.
I usually let the Windows admin dictate the name.

In this example, the username is SupportStaff/Managers. In order to have a successful
implementation, you can use the following command to test the LDAP authentication:

“test aaa-server authentication Company1-LDAP host 10.1.1.2 username
SupportStaff password abc123“.

“test aaa-server authentication Company1-LDAP host 10.1.1.2 username
Managers password abc123“.

!

If the test fails, I recommend you stop and figure out the AD problems first.

use this command on a domain controller to find the full path of the ASAuser account:

dsquery user -samid ASAUser

Your login DN has to contain the complete location of the user ID you are using.
For example CN=ASAUser,OU=ServiceAccounts,DC=cisco,DC=com

Then Create access lists for the split-tunnel policy (if appropriate) and for any traffic
filters you wish to apply to the IPSEC VPN.

access-list Managers-Split-Tunnel standard permit host 10.1.1.15
access-list Managers-Split-Tunnel standard permit host 10.1.1.25
access-list Support-Split-Tunnel standard permit 10.0.0.0 255.0.0.0

vpn-filter for ALLOWManagerAccess

access-list Restrict-Manager-Access extended permit tcp any host 10.1.1.15 eq smtp
access-list Restrict-Manager-Access extended permit tcp any host 10.1.1.25 eq www
access-list Restrict-Manager-Access extended deny ip any any

Define an IP address pool for remote users;

ip local pool ssl_vpn_pool 10.9.9.1-10.9.9.100 mask 255.255.255.0

Define your group-policies. These determine if a user can login and once logged in what
access they have by tying back to the access-lists. Also a policy needs to be created that
d
enies access. The LDAP map links policies to users and the NOACCESS policy is defined in the
tunnel group as the default policy.

group-policy ALLOWSupportAccess internal
group-policy ALLOWSupportAccess attributes
banner value Welcome you are logged in with Support rights and full access.
dns-server value 10.1.2.3
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Support-Split-Tunnel
default-domain value company1.co.uk
nem enable
!
group-policy ALLOWManagerAccess internal
group-policy ALLOWManagerAccess attributes
banner value You are logged in as a Manager with limited access.
dns-server value 10.1.2.3
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
vpn-filter value Restrict-Manager-Access
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Manager-Split-Tunnel
default-domain value company1.co.uk
nem enable
hidden-shares none
file-entry disable
file-browsing disable

!
!

group-policy NOACCESS internal
group-policy NOACCESS attributes
vpn-simultaneous-logins 0
vpn-tunnel-protocol ikev1 l2tp-ipsec

Finally the tunnel-group sets the various settings for IPSEC VPN access to the Cisco ASA
and ties the other parts of the config together.

tunnel-group REMOTEVPN type remote-access
tunnel-group REMOTEVPN general-attributes
address-pool ssl_vpn_pool
authentication-server-group Company1-LDAP
authorization-server-group Company1-LDAP
authorization-server-group (inside) Company1-LDAP
default-group-policy NOACCESS
password-management password-expire-in-days 7
authorization-required


To troubleshoot any issues enable the following debugs.

debug aaa authentication enabled at level 1
debug aaa authorization enabled at level 1
debug aaa common enabled at level 15
debug ldap enabled at level 15
!
show aaa-server protocol ldap

use this command on a domain controller to find the full path of the ASAuser account:

dsquery user -samid ASAUser

Summary :

ldap attribute-map Company1-Map
map-name memberOf IETF-Radius-Class
map-value memberOf “CN=SupportStaff,OU=User Accounts,DC=1stquote,DC=co,DC=uk”
ALLOWSupportAccess
map-value memberOf “CN=Managers,OU=User Accounts,DC=1stquote,DC=co,DC=uk”
ALLOWManagerAccess
!
aaa-server Company1-LDAP protocol ldap
aaa-server Company1-LDAP (inside) host 10.1.1.2
ldap-base-dn dc=company1,dc=co,dc=uk
server-port 389
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password globalwave
ldap-login-dn CN=Administrator,CN=Users,DC=company1,DC=co,DC=uk
server-type microsoft
ldap-attribute-map Company1-Map
!

access-list Managers-Split-Tunnel standard permit host 10.1.1.15
access-list Managers-Split-Tunnel standard permit host 10.1.1.25
access-list Support-Split-Tunnel standard permit 10.0.0.0 255.0.0.0

!
ip local pool ssl_vpn_pool 10.9.9.1-10.9.9.100 mask 255.255.255.0
!
group-policy ALLOWSupportAccess internal
group-policy ALLOWSupportAccess attributes
banner value Welcome you are logged in with Support rights and full access.
dns-server value 10.1.2.3
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Support-Split-Tunnel
default-domain value company1.co.uk
nem enable
!
group-policy ALLOWManagerAccess internal
group-policy ALLOWManagerAccess attributes
banner value You are logged in as a Manager with limited access.
dns-server value 10.1.2.3
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
vpn-filter value Restrict-Manager-Access
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Manager-Split-Tunnel
default-domain value company1.co.uk
nem enable
hidden-shares none
file-entry disable
file-browsing disable
!
!
group-policy NOACCESS internal
group-policy NOACCESS attributes
vpn-simultaneous-logins 0
vpn-tunnel-protocol ikev1 l2tp-ipsec
!
tunnel-group REMOTEVPN type remote-access
tunnel-group REMOTEVPN general-attributes
address-pool ssl_vpn_pool
authentication-server-group Company1-LDAP
authorization-server-group Company1-LDAP
authorization-server-group (inside) Company1-LDAP
default-group-policy NOACCESS
password-management password-expire-in-days 7
authorization-required

ASA 7.x/8.x Easy VPN with an ASA 5500 as the Server

ASA Version 7.0(4)

!

hostname ASA5520-704
enable password 8Ry2YjIyt7RRXU24 encrypted
names

!

!— Configure the outside and inside interfaces.


interface GigabitEthernet0/0
nameif outside
security-level 0
ip address 10.20.20.1 255.255.255.0
!

interface GigabitEthernet0/1
nameif inside
security-level 100
ip address 172.22.1.1 255.255.255.0

!
interface GigabitEthernet0/2
shutdown
no nameif
no security-level
no ip address
!

interface GigabitEthernet0/3
shutdown
no nameif
no security-level
no ip address
!

interface Management0/0
shutdown
no nameif
no security-level
no ip address
!

passwd 2KFQnbNIdI.2KYOU encrypted
ftp mode passive

!
ip local pool remoteuserspool 172.22.1.10-172.22.1.20 mask 255.255.255.0
!

!— This access list is used for a nat zero command that prevents
!— traffic which matches the access list from undergoing
!— network address translation (NAT).

access-list no-nat extended permit ip 172.22.1.0 255.255.255.0
172.16.1.0 255.255.255.0

!..ASA V8  nonat configuration changes:

object-group network obj-local_ipsec_tunnel
network-object 172.16.0.0 255.255.0.0
!

object-group network obj-remote_ipsec_tunnel
network-object 172.16.20.0 255.255.255.0
!

nat (inside,outside) source static obj-local_ipsec_tunnel
obj-local_ipsec_tunnel
destination static obj-remote_ipsec_tunnel
obj-remote_ipsec_tunnel

!— This access list is used to define the traffic
!— that should pass through the tunnel.
!— It is bound to the group policy which defines
!— a dynamic crypto map.

access-list split_tunnel extended permit ip 172.22.1.0 255.255.255.0

!
pager lines 24
mtu outside 1500
mtu inside 1500
no failover
icmp permit any echo-reply outside
icmp permit any inside
no asdm history enable
arp timeout 14400

!— Specify the NAT configuration.
!— NAT 0 prevents NAT for the ACL defined in this configuration.
!— The nat 1 command specifies NAT for all other traffic.

global (outside) 1 interface
nat (inside) 0 access-list no-nat
nat (inside) 1 0.0.0.0 0.0.0.0
route outside 0.0.0.0 0.0.0.0 10.20.20.2 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00
timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute

!…ASA V8 Nat configuration changes :

object network Private_Lan
subnet 172.16.0.0 255.255.0.0
nat (inside,outside) dynamic interface

!— This defines the group policy you use with EasyVPN.
!— Specify the networks
!— that should pass through the tunnel and that you want to
!— use network extension mode.

group-policy myGROUP internal
group-policy myGROUP attributes
dns-server value 172.22.1.1,172.22.1.2
vpn-tunnel-protocol IPSec
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value split_tunnel
default-domain value stknetwork.local
nem enable
!

!— Here the username and password associated with
!— this VPN connection are defined.  You
!— can also use AAA for this function.

username cisco password 3USUcOPFUiMCO4Jk encrypted
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart

!— PHASE 2 CONFIGURATION —!

!— The encryption types for Phase 2 are defined here.
!— A single DES encryption with !— the md5 hash algorithm is used.


crypto ipsec transform-set mySET esp-des esp-md5-hmac

!— Defines a dynamic crypto map with !— the specified encryption settings.

crypto dynamic-map myDYN-MAP 10 set transform-set mySET

!—– Configuring the IPsec Security Association Idle Timers feature increases the
!—– availability of resources by deleting SAs associated with idle peers.

crypto dynamic-map myDYN-MAP  10 set security-association lifetime seconds 86400
crypto dynamic-map myDYN-MAP 10 set security-association lifetime kilobytes 9908000

!— Enable Reverse Route Injection (RRI), which allows the Security Appliance
!— to learn routing information for connected clients.

crypto dynamic-map myDYN-MAP 10 set reverse-route

!— Binds the dynamic map to the IPsec/ISAKMP process.

crypto dynamic-map myMAP 10 ipsec-isakmp dynamic myDYN-MAP

!— Specifies the interface to be used with
!— the settings defined in this configuration.

crypto map myMAP interface outside

!— PHASE 1 CONFIGURATION —!

!— This configuration uses isakmp policy 1.
!— Policy 65535 is included in the default
!— configuration.  The configuration commands here define the Phase
!— 1 policies that are used.

isakmp enable outside
isakmp policy 1 authentication pre-share
isakmp policy 1 encryption des
isakmp policy 1 hash md5
isakmp policy 1 group 2
isakmp policy 1 lifetime 86400
!
isakmp policy 65535 authentication pre-share
isakmp policy 65535 encryption 3des
isakmp policy 65535 hash sha
isakmp policy 65535 group 2
isakmp policy 65535 lifetime 86400

!— The tunnel-group commands bind the configurations
!— defined in this configuration to the tunnel that is
!— used for EasyVPN. This tunnel name is the one specified on the remote side.

tunnel-group mytunnel type ipsec-ra
tunnel-group mytunnel general-attributes
address-pool remoteuserspool
authentication-server-group LOCAL
default-group-policy myGROUP
tunnel-group mytunnel ipsec-attributes

!— The pre-shared-key used here is “cisco”.

pre-shared-key *

!
telnet timeout 5 ssh
timeout 5 console timeout 0
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map global_policy
class inspection_default
inspect dns maximum-length 512
inspect ftp
inspect h323 h225
inspect h323 ras
inspect netbios
inspect rsh
inspect rtsp
inspect skinny
inspect esmtp
inspect sqlnet
inspect sunrpc
inspect tftp
inspect sip
inspect xdmcp
!
service-policy global_policy global

Summary :

username test1 password password1 encrypted privilege 0
!
ip local pool remoteuserspool 192.168.10.160-192.168.10.161 mask 255.255.255.0
!
access-list no-nat extended permit ip 172.22.1.0 255.255.255.0172.16.1.0 255.255.255.0

!..ASA V8  nonat configuration changes :

object-group network obj-local_ipsec_tunnel
network-object 172.16.0.0 255.255.0.0
!
object-group network obj-remote_ipsec_tunnel
network-object 172.16.20.0 255.255.255.0
!
nat (inside,outside) source static obj-local_ipsec_tunnel
obj-local_ipsec_tunnel destination static obj-remote_ipsec_tunnel
obj-remote_ipsec_tunnel
!

access-list split_tunnel extended permit ip 172.22.1.0 255.255.255.0
!
global (outside) 1 interface
nat (inside) 0 access-list no-nat
nat (inside) 1 0.0.0.0 0.0.0.0
route outside 0.0.0.0 0.0.0.0 10.20.20.2 1

!…ASA V8 Nat configuration changes :

object network Private_Lan
subnet 172.16.0.0 255.255.0.0
nat (inside,outside) dynamic interface
!
!
group-policy myGROUP internal
group-policy myGROUP attributes
dns-server value 172.22.1.1,172.22.1.2
vpn-tunnel-protocol IPSec
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value split_tunnel
default-domain value stknetwork.local
nem enable
!

!— PHASE 1 CONFIGURATION —

!

isakmp policy 1 authentication pre-share
isakmp policy 1 encryption des
isakmp policy 1 hash md5
isakmp policy 1 group 2
isakmp policy 1 lifetime 86400

!— PHASE 2 CONFIGURATION —

!

crypto ipsec transform-set mySET esp-des esp-md5-hmac
crypto dynamic-map dynmap 10 set transform-set mySET
dynamic-map dynmap 10 set security-association lifetime seconds 86400
crypto dynamic-map dynmap 10 set security-association lifetime kilobytes 9908000
crypto dynamic-map dynmap 10 set reverse-route
crypto map myMAP 10 ipsec-isakmp dynamic dynmap
!
crypto map myMAP interface outside
isakmp enable outside

!— Tunnel-Group CONFIGURATION —

!

tunnel-group mytunnel type ipsec-ra
tunnel-group mytunnel general-attributes
address-pool remoteuserspool
authentication-server-group LOCAL
default-group-policy myGROUP
tunnel-group mytunnel ipsec-attributes
pre-shared-key *
!

Option Configuration without creating a ” remoteuserspool” address :

vpn-group-policy myGROUP
vpn-tunnel-protocol IPSec
vpn-framed-ip-address 192.168.10.160 255.255.255.0
!

Option Configuration without creating a LOCAL DATABASE user account for Authentication :

!

vpn-group-policy myGROUP
username user1 password pass1 encrypted privilege 0 username user1
attributes

Cisco AAA login authentication with Radius (MS IAS)

1) Configure IAS

Click “Start>Programs>Administrative Tools>Internet Authentication Service”

*** Create Remote access Policy ***

Select “Remote Access Policies”
(right pane) Delete all policies
(right pane) Right-Click and Select “New Remote Access Policy”
Click “Next” Select “Set up a custom policy” and give it a name
Click “Next”
Click “Add”
Select “Windows Groups”
Click “Add” Type “Domain Admins” (or any other group you would like to use)
Click “Ok”
Click “Next”
Select “Grant remote access permission”
Click “Next”
Click “Edit Profile”
Select the “Authentication” tab
Select “Unencrypted Authentication” only
Select the “Advanced” tab
Change the service-type from “framed” to “login”
Delete “Framed-Protocol” Click “Add”
Select “Vendor Specific” Click “Add”
Select “Cisco” from the drop-down box
Select “Yes. It conforms” Click “Configure Attribute”
Change Attribute Number to “1”
Set the Attribute Format to “String”
Type “shell:priv-lvl=15” in the Attribute Value field
Click “Ok”
Click “Ok”
Click “Close”
Click “Next”
Click “Finish”

*** Add Radius Clients ***

Click “RADIUS Clients”
Right-Click and click “New Radius Client”
Give the client a friendly name and enter the ip address
Click “Next”
Enter a shared secret password
Click “Finish”

=========================================
3) Configure Cisco Device
=========================================

*** IOS Configuration ***


aaa new-model
radius-server host 192.168.10.100 key P@ssw0rd
ip radius source-interface f0/0
aaa authentication login default group radius
!
local line vty 0 4
login authentication default


*** PIX Configuration ***

username blindhog password Raz0rb4ck

aaa-server RADIUS (inside) host 192.168.10.100 P@ssw0rd
aaa-server LOCAL protocol local

aaa authentication ssh console RADIUS LOCAL
aaa authentication telnet console RADIUS LOCAL

Cisco ASA LDAP Active Directory Radius IAS.

!— Specify the interface which points toward the DNS server
!— to enable the ASA/PIX to use DNS.

dns domain-lookup inside
dns server-group DefaultDNS
timeout 30

*****************************************************

!— Specify the location of the DNS server in the DefaultDNS group.

name-server 172.16.1.1
domain-name cisco.com

*****************************************************

!— This access list is used for a nat zero command that prevents
!— traffic which matches the access list from undergoing NAT.

access-list 101 extended permit ip 172.16.0.0 255.255.0.0 10.16.20.0 255.255.255.0

!..ASA V8  nonat configuration changes :

object-group network obj-local_ipsec_tunnel
network-object 172.16.0.0 255.255.0.0

!
object-group network obj-remote_ipsec_tunnel
network-object 172.16.20.0 255.255.255.0
!

nat (inside,outside) source static obj-local_ipsec_tunnel
obj-local_ipsec_tunnel
destination static obj-remote_ipsec_tunnel
obj-remote_ipsec_tunnel

*****************************************************

!….Corporate Network Behind The ASA.  Split tunneling allows users to send only that
traffic which is destined for the corporate network across the tunnel. All other traffic
such as instant messaging, email, or casual browsing is sent out to the Internet via the
local LAN of the VPN Client.

access-list split_tunnel standard permit 172.16.0.0 255.255.0.0

*****************************************************

!— Create a pool of addresses from which IP addresses are assigned
!— dynamically to the remote VPN Clients.

ip local pool vpnclient 10.16.20.1-10.16.20.5

*****************************************************

!— NAT 0 prevents NAT for networks specified in the ACL 101.
!— The nat 1 command specifies Port Address Translation (PAT)
!— using 10.10.1.5 for all other traffic.

global (outside) 1 10.10.1.5
nat (inside) 0 access-list 101
nat (inside) 1 0.0.0.0 0.0.0.0


!…ASA V8 Nat configuration changes :

object network Private_Lan
subnet 172.16.0.0 255.255.0.0
nat (inside,outside) dynamic interface

*****************************************************

!—ip routes

route outside 10.10.0.0 255.255.255.0 10.10.1.1 1
route inside 172.16.0.0 255.255.0.0 10.11.1.3 1
route outside 0.0.0.0 0.0.0.0 10.11.1.1 1

*****************************************************

!— Create the AAA server group “vpn” and specify the protocol as RADIUS.
!— Specify the IAS server as a member of the “vpn” group and provide the
!— location and key.

aaa-server vpn protocol radius
aaa-server vpn host 10.11.1.2
key cisco123

*****************************************************

!— Create the VPN users’ group policy and specify the DNS server IP address
!— and the domain name in the group policy.

group-policy vpn3000 internal
group-policy vpn3000 attributes
dns-server value 172.16.1.1
split-tunnel-policy tunnelspecified
split-tunnel-network-list value 101

default-domain value cisco.com

*****************************************************

!— In order to identify remote access users to the Security Appliance,
!— you can also configure usernames and passwords on the device
!— in addition to using AAA.

username vpn3000 password nPtKy7KDCerzhKeX encrypted

*****************************************************

!— PHASE 2 CONFIGURATION —!
!— The encryption types for Phase 2 are defined here.
!— A single DES encryption with
!— the md5 hash algorithm is used.

crypto ipsec transform-set my-set esp-des esp-md5-hmac

*****************************************************

!— Defines a dynamic crypto map with
!— the specified encryption settings.

crypto dynamic-map dynmap 10 set transform-set my-set

*****************************************************

!— Configuring the IPsec Security Association Idle Timers feature increases the
availability of resources by deleting SAs associated with idle peers.
IPsec Security Association Idle Timers feature prevents the wasting of resources
by idle peers, more resources will be available to create new SAs as required.

crypto dynamic-map dynmap 10 set security-association lifetime seconds 86400
crypto dynamic-map dynmap 10 set security-association lifetime kilobytes 9908000

*****************************************************

!— Enable Reverse Route Injection (RRI), which allows the Security Appliance
!— to learn routing information for connected clients.

crypto dynamic-map dynmap 10 set reverse-route

*****************************************************

!— Binds the dynamic map to the IPsec/ISAKMP process.

crypto map mymap 10 ipsec-isakmp dynamic dynmap

*****************************************************

!— Specifies the interface to be used with
!— the settings defined in this configuration.

crypto map mymap interface outside

!— Allowing the decrypted IPSEC packets to be permitted
even if the outside interface ACL does not explicitly allow for it.

sysopt connection permit-ipsec

!— For traffic that enters the security appliance through a VPN tunnel and is then
decrypted, to allow the traffic to bypass interface access lists.

!—You might want to bypass interface access lists for decrypted VPN traffic to simplify
configuration and to maximize the security appliance performance. If you disable this
feature, you must apply an access list to the ingress interface that permits decrypted
VPN packets from all VPN peers

sysopt connection permit-vpn

!— To ensure that the maximum TCP segment size does not exceed the value you
set and that the maximum is not less than a specified size.

sysopt connection tcpmss

!— NAT-Traversal or NAT-T allows VPN traffic to pass through NAT or PAT devices,
such as a Linksys SOHO router. If NAT-T is not enabled, VPN Client users often appear
to connect to the PIX or ASA without a problem, but they are unable to access the internal
network behind the security appliance.
!
no isakmp nat-traversal 20

*****************************************************

!— PHASE 1 CONFIGURATION —!
!— This configuration uses ISAKMP policy 10.
!— Policy 65535 is included in the configuration by default.
!— The configuration commands here define the Phase
!— 1 policy parameters that are used.

isakmp enable outside
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 1000

!

isakmp policy 65535 authentication pre-share
isakmp policy 65535 encryption 3des
isakmp policy 65535 hash sha
isakmp policy 65535 group 2
isakmp policy 65535 lifetime 86400

*****************************************************

!— The Security Appliance provides the default tunnel groups
!— for remote access (DefaultRAGroup).

tunnel-group DefaultRAGroup general-attributes
authentication-server-group (outside) vpn

*****************************************************

!— Create a new tunnel group and set the connection
!— type to IPsec remote access (ipsec-ra).

tunnel-group vpn3000 type ipsec-ra

*****************************************************

!— Associate the vpnclient pool to the tunnel group using the address pool.
!— Associate the AAA server group (VPN) with the tunnel group.

tunnel-group vpn3000 general-attributes
address-pool vpnclient
authentication-server-group vpn
default-group-policy vpn3000

*****************************************************

!— Enter the pre-shared-key to configure the authentication method.

tunnel-group vpn3000 ipsec-attributes
pre-shared-key *

*****************************************************

Configuration Summary :

access-list 101 extended permit ip 172.16.0.0 255.255.0.0 10.16.20.0 255.255.255.0
access-list split_tunnel standard permit 172.16.0.0 255.255.0.0
ip local pool vpnclient 10.16.20.1-10.16.20.5
!
object-group network obj-local_ipsec_tunnel
network-object 172.16.0.0 255.255.0.0
object-group network obj-remote_ipsec_tunnel
network-object 172.16.20.0 255.255.255.0
!
nat (inside,outside) source static obj-local_ipsec_tunnel
obj-local_ipsec_tunnel destination static obj-remote_ipsec_tunnel
obj-remote_ipsec_tunnel
!
aaa-server vpn protocol radius
aaa-server vpn host 10.11.1.2
key cisco123
!
group-policy vpn3000 internal
group-policy vpn3000 attributes
dns-server value 172.16.1.1
split-tunnel-policy tunnelspecified
split-tunnel-network-list value 101
default-domain value cisco.com
!
crypto ipsec transform-set my-set esp-des esp-md5-hmac
crypto dynamic-map dynmap 10 set transform-set my-set
crypto dynamic-map dynmap 10 set security-association lifetime seconds 86400
crypto dynamic-map dynmap 10 set security-association lifetime kilobytes 9908000
crypto dynamic-map dynmap 10 set reverse-route
crypto map mymap 10 ipsec-isakmp dynamic dynmap
!
crypto map mymap interface outside
sysopt connection permit-ipsec
sysopt connection permit-vpn
sysopt connection tcpmss
no isakmp nat-traversal 20
!
isakmp enable outside
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption des
isakmp policy 10 hash md5
isakmp policy 10 group 2
isakmp policy 10 lifetime 1000

!
tunnel-group DefaultRAGroup general-attributes
authentication-server-group (outside) vpn
tunnel-group vpn3000 type ipsec-ra
tunnel-group vpn3000 general-attributes
address-pool vpnclient
authentication-server-group vpn
default-group-policy vpn3000
tunnel-group vpn3000 ipsec-attributes
pre-shared-key *

*********************************************************************

VPN Client 4.8 Configuration

Complete these steps to configure the VPN Client 4.8.

  1. Select Start > Programs > Cisco Systems VPN Client > VPN Client.
  2. Click New to launch the Create New VPN Connection Entry window.

!
!
!
!
!
!
!
!
!
3. Enter the name of the Connection Entry along with a description. Enter the outside
IP address of the PIX Firewall in the Host box. Then enter the VPN Group name and
password and click Save.

!
!
!
!
!
!
!
!
!
!
!
!
!
4. Click on the connection you would like to use and click Connect from the VPN Client main window.

!

5. When prompted, enter the Username and Password information for xauth and click OK
to connect to the remote network.

!
!
!
!
!
!
6. The VPN Client gets connected with the PIX at the central site

!
!
!
!
!
!
!
!
!
Select Status > Statistics to check the tunnel statistics of the VPN Client

!
!
!
!
!
!
!
!
!
!
!

*************************************************************

Complete these steps to configure the Microsoft Windows 2003 server with IAS.

Note: These steps assume that IAS is already installed on the local machine. If not,
add this through Control Panel > Add/Remove Programs.

  1. Select Administrative Tools > Internet Authentication Service and right-click
    on RADIUS Client to add a new RADIUS client. When you have typed the client
    information, click OK.

    This example shows a client named Pix with an IP address of 10.11.1.1.
    Client-Vendor is set to RADIUS Standard, and the shared secret is cisco123.

    !
    !
    !
    !
    !
    !
    !
    !
    !
    !
    !
    !
    1. Go to Remote Access Policies, right-click on Connections to Other Access Servers,and select Properties.

    2. Ensure that the option for Grant Remote Access Permissions is selected.
    Click Edit Profile and check these settings:

      • On the Authentication tab, check Unencrypted authentication (PAP, SPAP),
        MS-CHAP, and MS-CHAP-v2
        .
      • On the Encryption tab, ensure that the option for No Encryption is selected.

      !
      !
      !
      !
      !
      !
      !
      !
      !

      1. Select Administrative Tools > Computer Management > System Tools > Local Users and Groups, right-click on Users and select New Users to add a user into the local computer account.
      2. Add a user with Cisco password password1 and check this profile information:
        • On the General tab, ensure that the option for Password Never Expired
          is selected instead of the option for User Must Change Password.
        • On the Dial-in tab, select the option for Allow access (or leave the default setting
          of Control access through Remote Access Policy).

        Click OK when you are finished.

        !
        !
        !
        !
        !
        !
        !
        !
        !
        !
        !
        !
        !

        The security appliance supports password management for the RADIUS and LDAP
        protocols. It supports the password-expire-in-days option for LDAP only.

        You can configure password management for IPSec remote access and
        SSL VPN tunnel-groups.

        When you configure the password-management command, the security
        appliance notifies the remote user at login that the current password of the user
        is about to expire or has expired. The security appliance then offers the user the
        opportunity to change the password. If the current password has not yet expired,
        the user can still log in with that password.

        This command is valid for AAA servers that support such notification.
        The security appliance ignores this command if RADIUS or LDAP authentication
        has not been configured.

        When a user password expires and the user attempts to log with a VPN client to the
        ASA, the Password needs to be changed but password management
        disabled
        error message appears on the Cisco client software.

        Enable Password-Management with the password-management command in the
        tunnel group general attributes mode in order to resolve this issue.

        This is a sample configuration for Password-Expiry :

        tunnel-group <Tunnel-group> type remote-access
        tunnel-group <Tunnel-group> general-attributes
        authentication-server-group LDAP-AD
        default-group-policy DfltGrpPolicy
        password-management password-expire-in-days <number of days>

        !—- From the PIX, use the Test keyword with the aaa authentication command
        in global configuration mode in order to verify the user authentication with the
        AAA server. After you enter the command, the PIX prompts you to enter the username and password to validate.When the user credential is verified and it
        is valid, you recieve the Authentication Successful message.

        pix(config-aaa-server-host)#test aaa authentication radius host 10.11.1.2

        Username: administrator
        Password: *****

        
        
        

ASA v8.2 LDAP EASY VPN SERVER

name 172.18.1.0 RATHBONE_VPN_POOL
name 172.16.0.0 LAN40
name 10.10.10.0 VLAN60_Internet
name 172.16.1.5 DC1

!
!
object network Private_Lan
subnet 172.16.0.0 255.255.0.0
!
object-group network obj-local_ipsec_tunnel
network-object LAN40 255.255.0.0

!
object-group network obj-remote_ipsec_tunnel
network-object RATHBONE_VPN_POOL 255.255.255.0
!

access-list FIREWALL_GW_cryptomap_1 standard permit 172.16.0.0 255.255.0.0
!
!
ip local pool RATHBONE_VPN_POOL 172.18.1.1-172.18.1.254 mask 255.255.255.0

!
nat (FIREWALL_FW,FIREWALL_GW) source static obj-local_ipsec_tunnel
obj-local_ipsec_tunnel destination static obj-remote_ipsec_tunnel obj-remote_ipsec_tunnel
!
!

object network Private_Lan
nat (FIREWALL_FW,FIREWALL_GW) dynamic interface

!
route FIREWALL_GW 0.0.0.0 0.0.0.0 192.168.2.2 1
route FIREWALL_GW VLAN60_Internet 255.255.255.0 192.168.2.1 1
route FIREWALL_FW LAN40 255.255.0.0 192.168.1.1 1
route FIREWALL_FW RATHBONE_VPN_POOL 255.255.255.0 192.168.1.1 1

!
!
ldap attribute-map RATHBONEMAP
map-name  memberOf IETF-Radius-Class
map-value memberOf CN=RemoteVPN,OU=RemoteUsers,DC=rathboneuk,DC=local AllowRemoteUsers
dynamic-access-policy-record DfltAccessPolicy

!
aaa-server Rathbone_LDAP protocol ldap
!

aaa-server Rathbone_LDAP (FIREWALL_FW) host DC1
server-port 389
ldap-base-dn dc=rathboneuk,dc=local
ldap-group-base-dn dc=rathboneuk,dc=local
ldap-scope subtree
ldap-naming-attribute sAMAccountname
ldap-login-password globalwave
ldap-login-dn CN=Administrator,CN=Users,DC=rathboneuk,DC=local

server-type microsoft
ldap-attribute-map RATHBONEMAP

!

******************************************************************

As we continue with the sub commands, we provide a username and password for the
ASA to use in order to log into AD and make sure the user exists.
I usually let the Windows admin dictate the name.

In this example, the username is Administrator. In order to have a successful
implementation, you can use the following command to test the LDAP authentication:

“test aaa-server authentication Rathbone_LDAP host 10.1.1.2 username
Administrator password globalwave“.

If the test fails, I recommend you stop and figure out the AD problems first.

use this command on a domain controller to find the full path of the ASAuser account:

dsquery user -samid ASAUser

Your login DN has to contain the complete location of the user ID you are using.
For example CN=ASAUser,OU=ServiceAccounts,DC=cisco,DC=com

******************************************************************

!
crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
!
crypto dynamic-map Rathbone_Vpn 1 set ikev1 transform-set ESP-3DES-MD5
crypto dynamic-map Rathbone_Vpn 1 set security-association lifetime seconds 86400

crypto dynamic-map Rathbone_Vpn 1 set security-association lifetime kilobytes 9908000
crypto dynamic-map Rathbone_Vpn 1 set reverse-route
!

crypto map FIREWALL_GW 10 ipsec-isakmp dynamic Rathbone_Vpn
!
no crypto isakmp nat-traversal
sysopt connection permit-ipsec

!
crypto ikev1 enable FIREWALL_GW

!
crypto ikev1 policy 10
authentication pre-share
encryption 3des
hash md5
group 2
lifetime 86400

!
!
group-policy
AllowRemoteUsers internal
group-policy AllowRemoteUsers attributes
banner value Welcome you are logged in with Support rights and full access
dns-server value 172.16.1.5 172.16.1.14
vpn-simultaneous-logins 1
vpn-idle-timeout none

vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value FIREWALL_GW_cryptomap_1

default-domain value rathboneuk.local
nem enable

!
group-policy NOACCESS internal
group-policy NOACCESS attributes
vpn-simultaneous-logins 0
vpn-tunnel-protocol ikev1 l2tp-ipsec
!
tunnel-group RATHBONEVPN type remote-access
tunnel-group RATHBONEVPN general-attributes

address-pool RATHBONE_VPN_POOL
authentication-server-group Rathbone_LDAP
default-group-policy NOACCESS
password-management password-expire-in-days 30
authorization-required
!
tunnel-group RATHBONEVPN ipsec-attributes
ikev1 pre-shared-key rathbone
isakmp keepalive threshold 20 retry 10

!
!
To troubleshoot any issues enable the following debugs.

debug aaa authentication enabled at level 1
debug aaa authorization enabled at level 1
debug aaa common enabled at level 15
debug ldap enabled at level 15

!
!

Remove Configuration :

no nat (FIREWALL_FW,FIREWALL_GW) source static obj-local_ipsec_tunnel obj-local_ipsec_tunnel destination static obj-remote_ipsec_tunnel obj-remote_ipsec_tunnel
!
no access-list FIREWALL_GW_cryptomap_1 standard permit 172.16.0.0 255.255.0.0
!
no ip local pool RATHBONE_VPN_POOL 172.18.1.1-172.18.1.254 mask 255.255.255.0
!
no name 172.18.1.0 RATHBONE_VPN_POOL
no name 172.16.0.0 LAN40
no name 10.10.10.0 VLAN60_Internet
no name 172.16.1.5 DC1
!
!
object network Private_Lan
no nat (FIREWALL_FW,FIREWALL_GW) dynamic interface
exit
no object network Private_Lan
!
no route FIREWALL_GW 0.0.0.0 0.0.0.0 192.168.2.2 1
no route FIREWALL_GW VLAN60_Internet 255.255.255.0 192.168.2.1 1
no route FIREWALL_FW LAN40 255.255.0.0 192.168.1.1 1
no route FIREWALL_FW RATHBONE_VPN_POOL 255.255.255.0 192.168.1.1 1 !
!
no ldap attribute-map RATHBONEMAP
!
no aaa-server Rathbone_LDAP protocol ldap
no aaa-server Rathbone_LDAP (FIREWALL_FW) host DC1
!
no crypto map FIREWALL_GW 10 ipsec-isakmp dynamic Rathbone_Vpn
no crypto dynamic-map Rathbone_Vpn 1
no crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
!
no crypto isakmp nat-traversal
no sysopt connection permit-ipsec
!
no crypto ikev1 enable FIREWALL_GW
!
no crypto ikev1 policy 10
!
no group-policy AllowRemoteUsers internal
no group-policy AllowRemoteUsers attributes

!
no group-policy NOACCESS internal
no group-policy NOACCESS attributes

!
clear configure tunnel-group RATHBONEVPN

ASA VPN LDAP Authentication + Group Membership Verification


!
!
!
!
!
!
!
!
!
!

Project Goal: The goal for this task is to authenticate VPN users via LDAP to the
Windows 2008 domain controllers. In addition to the simple AD authentication
requirement, the client wanted to match the user’s credentials against a VPN group
in the AD database, as a second layer of protection.

This second check against the AD group membership helps to ensure that the user
didn’t just obtain the VPN group password along with a user’s username and password.
In addition, it gives more control to the IT administrator to make sure that only approved
users have VPN access, not all users in the AD branch.

Requirements: In order to complete this task, the following items were needed:

1. Upgrade the ASA appliance to 8.0(4). At the time of the project, this version was
stable and allowed authentication directly to AD without the need for an additional
RADIUS services to be installed on the domain controllers.

2. A single user account with basic privileges in the AD database. For best results,
place this user in the root of the tree (Base DN).

I recommend building a test VPN group in parallel, test the authentication and then
change the production group’s authentication servers.

The first step is to create an attribute map called ASAMAP. In the map subcommands,
we match the well known Microsoft attribute
“memberOf” to a standard IETF Radius class,
which the ASA is familiar with.

The next line takes the newly created association to the path of the AD group,
in this example the group name is VPN_Users.

The final important note in this step is to notice the value being mapped to the already
existing VPN group called
ciscovpn. Now that the map name and value to be checked
has been created, it will later be associated with the VPN tunnel group.

ldap attribute-map ASAMAP
map-name memberOf IETF-Radius-Class
map-value memberOf “CN=VPN_Users,OU=Security                 Groups,OU=Groups,OU=CompanyXYZHQ,DC=companyxyz,DC=com” ciscovpn

Create the new AAA server(s) called LDAP-Auth2-AD (you can use any name you like).
In this case, these are the new 2008 servers. In addition, the communication protocol is
determined in this step. For our example, I use LDAP.

aaa-server LDAP-Auth2-AD protocol ldap

Now that we have identified the protocol as LDAP and created a new method,
we add each server independently. Just like anything else with the ASA, you must
tell it which interface to use in order to communicate with the server, in this case,
the (inside) interface. Larger clients might have their authentication servers in a DMZ.

After entering the following command, the rest of the commands are sub-commands.

aaa-server LDAP-Auth2-AD (inside) host 172.16.1.91

In this step we tell the ASA where the Base DN is for the AD tree.
This is basically the path to the root of the tree.

ldap-base-dn DC=CompanyXYZ,DC=com
ldap-scope subtree
ldap-naming-attribute sAMAccountName

As we continue with the sub commands, we provide a username and password for the
ASA to use in order to log into AD and make sure the user exists.
I usually let the Windows admin dictate the name.

In this example, the username is S_ASA_LDAP. In order to have a successful
implementation, you can use the following command to test the LDAP authentication:

“test aaa-server authentication LDAP-Auth2-AD host 172.16.1.91 username
S_ASA_LDAP password abc123“.

!

If the test fails, I recommend you stop and figure out the AD problems first.

use this command on a domain controller to find the full path of the ASAuser account:

dsquery user -samid ASAUser

Your login DN has to contain the complete location of the user ID you are using.
For example CN=ASAUser,OU=ServiceAccounts,DC=cisco,DC=com


!

ldap-login-password
ldap-login-dn CN=S_ASA_LDAP,OU=service accounts,OU=Users,
OU=CompanyXYZ HQ,DC=CompanyXYZ,DC=com
server-type Microsoft

Still in subcommands, we add our second layer of authentication by telling the ASA
to also check against the LDAP attribute created in step 1.

ldap-attribute-map ASAMAP

The next step is to point the existing production VPN tunnel group to the new
authentication servers created earlier.

First we enter the VPN group policy section, and then assign the appropriate
authentication method. Note, there are other attribute settings for this group,
however, we only care about the authentication method.

tunnel-group ciscovpn general-attributes
authentication-server-group LDAP-Auth2-AD

The ASA automatically defers to the default group policy if a user authentication
fails and no authentication method is specified, therefore, we need to make sure that
the built-in default policy is using the same authentication method.
The fiirst step is to change the default tunnel group defaultRAGroup to utilize the same
authentication method. Note: If you don’t perform these two steps, the authentication
will still work even if you remove the user from the AD group.

tunnel-group DefaultRAGroup general-attributes
authentication-server-group LDAP-Auth2-AD

Finally, the VPN default group policy attributes are basically disabled by changing
the simultaneous logins to zero.

group-policy DfltGrpPolicy attributes
vpn-simultaneous-logins 0

Now it is time to test. The ASA has a simple debug command to verify the results.

debug ldap 255

Here is a sample debug of the LDAP authentication. The only part we need for this
task is to make sure that the “memberOf” variable is being properly matched.
If the match is being performed properly, the rest depends on the users group
membership. Below we see a match with the “Users” group.

[20330] memberOf: value = CN=VPN_Users,OU=Security Groups,OU=Groups,
OU=CompanyXYZ HQ,DC=compnayxyz,DC=COM

[20330] mapped to IETF-Radius-Class: value = policy_1

In addition, the “debug ldap 255” command is very useful to see the Active Directly
Base DN path and what the server is expecting from the ASA.

In addition, this debug command can be very useful to find out where the authentication
maybe failing. For example, if the login fails, you can see if the issue was related to a
bad password, lack of communication with the server, or no group match.

Note: If you forget to disable the logins and authentication for the default VPN group,
you will see in the debug that the user is not a member of the VPN group,
yet authentication is still successful.

In conclusion, I have included a snippet from the actual running configuration:

ldap attribute-map ASAMAP
map-name memberOf IETF-Radius-Class
map-value memberOf “CN=VPN_Users,OU=Security Groups,OU=Groups,
OU=CompanyXYZ HQ,DC=CompanyXYZ,DC=com” ciscovpn
!
dynamic-access-policy-record DfltAccessPolicy
aaa-server LDAP-Auth2-AD protocol ldap
aaa-server LDAP-Auth2-AD (inside) host 172.16.1.91
ldap-base-dn DC=CompanyXYZ,DC=com
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password *
ldap-login-dn CN=S_ASA_LDAP,OU=service accounts,OU=Users,
OU=CompanyXYZ HQ,DC=CompanyXYZ,DC=com
server-type microsoft
ldap-attribute-map ASAMAP
!
aaa-server LDAP-Auth2-AD (inside) host 172.16.1.92
ldap-base-dn DC=CompanyXYZ,DC=com
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password *
ldap-login-dn CN=S_ASA_LDAP,OU=service accounts,OU=Users,
OU=CompanyXYZ HQ,DC=CompanyXYZ,DC=com
server-type microsoft
ldap-attribute-map ASAMAP
!
tunnel-group ciscovpn general-attributes
authentication-server-group LDAP-Auth2-AD
tunnel-group DefaultRAGroup general-attributes
authentication-server-group LDAP-Auth2-AD
group-policy DfltGrpPolicy attributes
vpn-simultaneous-logins 0