ASA VPN LDAP Authentication + Group Membership

The logic here will allow Remote VPN users to connect so long as they are a member of
either the SupportStaff or Managers group within the Microsoft active directory.
Members of the Managers group within the AD will have more restricted access that
members of SupportStaff.

If an AD user isn’t a member of one of these groups,they will be denied access.

The following key aspects of configuration need to be completed;

  • aaa-server
  • ldap attribute-map
  • access-lists
  • ip address pools
  • webvpn parameters
  • group-policy
  • tunnel-group

Configure Your AAA server details. The user “ldap_user” is a standard user within the
Microsoft AD, ideally this users password (ldap_users_password) should be set to never expire.

aaa-server Company1-LDAP protocol ldap
aaa-server Company1-LDAP (inside) host 10.1.1.2
ldap-base-dn dc=company1,dc=co,dc=uk
server-port 389
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password globalwave
ldap-login-dn CN=Administrator,CN=Users,DC=company1,DC=co,DC=uk
server-type microsoft
ldap-attribute-map
Company1-Map

!

Define your ldap attribute map. This will tell the Cisco ASA which locally configured
group policy to apply depending on the group membership status, within the Microsoft AD
of the user connecting via the SSL VPN.


ldap attribute-map Company1-Map
map-name memberOf IETF-Radius-Class
map-value memberOf “CN=SupportStaff,OU=User Accounts,DC=1stquote,DC=co,DC=uk”
ALLOWSupportAccess
map-value memberOf “CN=Managers,OU=User Accounts,DC=1stquote,DC=co,DC=uk”
ALLOWManagerAccess

As we continue with the sub commands, we provide a username and password for the
ASA to use in order to log into AD and make sure the user exists.
I usually let the Windows admin dictate the name.

In this example, the username is SupportStaff/Managers. In order to have a successful
implementation, you can use the following command to test the LDAP authentication:

“test aaa-server authentication Company1-LDAP host 10.1.1.2 username
SupportStaff password abc123“.

“test aaa-server authentication Company1-LDAP host 10.1.1.2 username
Managers password abc123“.

!

If the test fails, I recommend you stop and figure out the AD problems first.

use this command on a domain controller to find the full path of the ASAuser account:

dsquery user -samid ASAUser

Your login DN has to contain the complete location of the user ID you are using.
For example CN=ASAUser,OU=ServiceAccounts,DC=cisco,DC=com

Then Create access lists for the split-tunnel policy (if appropriate) and for any traffic
filters you wish to apply to the IPSEC VPN.

access-list Managers-Split-Tunnel standard permit host 10.1.1.15
access-list Managers-Split-Tunnel standard permit host 10.1.1.25
access-list Support-Split-Tunnel standard permit 10.0.0.0 255.0.0.0

vpn-filter for ALLOWManagerAccess

access-list Restrict-Manager-Access extended permit tcp any host 10.1.1.15 eq smtp
access-list Restrict-Manager-Access extended permit tcp any host 10.1.1.25 eq www
access-list Restrict-Manager-Access extended deny ip any any

Define an IP address pool for remote users;

ip local pool ssl_vpn_pool 10.9.9.1-10.9.9.100 mask 255.255.255.0

Define your group-policies. These determine if a user can login and once logged in what
access they have by tying back to the access-lists. Also a policy needs to be created that
d
enies access. The LDAP map links policies to users and the NOACCESS policy is defined in the
tunnel group as the default policy.

group-policy ALLOWSupportAccess internal
group-policy ALLOWSupportAccess attributes
banner value Welcome you are logged in with Support rights and full access.
dns-server value 10.1.2.3
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Support-Split-Tunnel
default-domain value company1.co.uk
nem enable
!
group-policy ALLOWManagerAccess internal
group-policy ALLOWManagerAccess attributes
banner value You are logged in as a Manager with limited access.
dns-server value 10.1.2.3
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
vpn-filter value Restrict-Manager-Access
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Manager-Split-Tunnel
default-domain value company1.co.uk
nem enable
hidden-shares none
file-entry disable
file-browsing disable

!
!

group-policy NOACCESS internal
group-policy NOACCESS attributes
vpn-simultaneous-logins 0
vpn-tunnel-protocol ikev1 l2tp-ipsec

Finally the tunnel-group sets the various settings for IPSEC VPN access to the Cisco ASA
and ties the other parts of the config together.

tunnel-group REMOTEVPN type remote-access
tunnel-group REMOTEVPN general-attributes
address-pool ssl_vpn_pool
authentication-server-group Company1-LDAP
authorization-server-group Company1-LDAP
authorization-server-group (inside) Company1-LDAP
default-group-policy NOACCESS
password-management password-expire-in-days 7
authorization-required


To troubleshoot any issues enable the following debugs.

debug aaa authentication enabled at level 1
debug aaa authorization enabled at level 1
debug aaa common enabled at level 15
debug ldap enabled at level 15
!
show aaa-server protocol ldap

use this command on a domain controller to find the full path of the ASAuser account:

dsquery user -samid ASAUser

Summary :

ldap attribute-map Company1-Map
map-name memberOf IETF-Radius-Class
map-value memberOf “CN=SupportStaff,OU=User Accounts,DC=1stquote,DC=co,DC=uk”
ALLOWSupportAccess
map-value memberOf “CN=Managers,OU=User Accounts,DC=1stquote,DC=co,DC=uk”
ALLOWManagerAccess
!
aaa-server Company1-LDAP protocol ldap
aaa-server Company1-LDAP (inside) host 10.1.1.2
ldap-base-dn dc=company1,dc=co,dc=uk
server-port 389
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password globalwave
ldap-login-dn CN=Administrator,CN=Users,DC=company1,DC=co,DC=uk
server-type microsoft
ldap-attribute-map Company1-Map
!

access-list Managers-Split-Tunnel standard permit host 10.1.1.15
access-list Managers-Split-Tunnel standard permit host 10.1.1.25
access-list Support-Split-Tunnel standard permit 10.0.0.0 255.0.0.0

!
ip local pool ssl_vpn_pool 10.9.9.1-10.9.9.100 mask 255.255.255.0
!
group-policy ALLOWSupportAccess internal
group-policy ALLOWSupportAccess attributes
banner value Welcome you are logged in with Support rights and full access.
dns-server value 10.1.2.3
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Support-Split-Tunnel
default-domain value company1.co.uk
nem enable
!
group-policy ALLOWManagerAccess internal
group-policy ALLOWManagerAccess attributes
banner value You are logged in as a Manager with limited access.
dns-server value 10.1.2.3
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
vpn-filter value Restrict-Manager-Access
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Manager-Split-Tunnel
default-domain value company1.co.uk
nem enable
hidden-shares none
file-entry disable
file-browsing disable
!
!
group-policy NOACCESS internal
group-policy NOACCESS attributes
vpn-simultaneous-logins 0
vpn-tunnel-protocol ikev1 l2tp-ipsec
!
tunnel-group REMOTEVPN type remote-access
tunnel-group REMOTEVPN general-attributes
address-pool ssl_vpn_pool
authentication-server-group Company1-LDAP
authorization-server-group Company1-LDAP
authorization-server-group (inside) Company1-LDAP
default-group-policy NOACCESS
password-management password-expire-in-days 7
authorization-required