Networking-Blog

My WordPress Blog

ASA VPN LDAP Authentication + Group Membership

The logic here will allow Remote VPN users to connect so long as they are a member of
either the SupportStaff or Managers group within the Microsoft active directory.
Members of the Managers group within the AD will have more restricted access that
members of SupportStaff.

If an AD user isn’t a member of one of these groups,they will be denied access.

The following key aspects of configuration need to be completed;

  • aaa-server
  • ldap attribute-map
  • access-lists
  • ip address pools
  • webvpn parameters
  • group-policy
  • tunnel-group

Configure Your AAA server details. The user “ldap_user” is a standard user within the
Microsoft AD, ideally this users password (ldap_users_password) should be set to never expire.

aaa-server Company1-LDAP protocol ldap
aaa-server Company1-LDAP (inside) host 10.1.1.2
ldap-base-dn dc=company1,dc=co,dc=uk
server-port 389
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password globalwave
ldap-login-dn CN=Administrator,CN=Users,DC=company1,DC=co,DC=uk
server-type microsoft
ldap-attribute-map
Company1-Map

!

Define your ldap attribute map. This will tell the Cisco ASA which locally configured
group policy to apply depending on the group membership status, within the Microsoft AD
of the user connecting via the SSL VPN.


ldap attribute-map Company1-Map
map-name memberOf IETF-Radius-Class
map-value memberOf “CN=SupportStaff,OU=User Accounts,DC=1stquote,DC=co,DC=uk”
ALLOWSupportAccess
map-value memberOf “CN=Managers,OU=User Accounts,DC=1stquote,DC=co,DC=uk”
ALLOWManagerAccess

As we continue with the sub commands, we provide a username and password for the
ASA to use in order to log into AD and make sure the user exists.
I usually let the Windows admin dictate the name.

In this example, the username is SupportStaff/Managers. In order to have a successful
implementation, you can use the following command to test the LDAP authentication:

“test aaa-server authentication Company1-LDAP host 10.1.1.2 username
SupportStaff password abc123“.

“test aaa-server authentication Company1-LDAP host 10.1.1.2 username
Managers password abc123“.

!

If the test fails, I recommend you stop and figure out the AD problems first.

use this command on a domain controller to find the full path of the ASAuser account:

dsquery user -samid ASAUser

Your login DN has to contain the complete location of the user ID you are using.
For example CN=ASAUser,OU=ServiceAccounts,DC=cisco,DC=com

Then Create access lists for the split-tunnel policy (if appropriate) and for any traffic
filters you wish to apply to the IPSEC VPN.

access-list Managers-Split-Tunnel standard permit host 10.1.1.15
access-list Managers-Split-Tunnel standard permit host 10.1.1.25
access-list Support-Split-Tunnel standard permit 10.0.0.0 255.0.0.0

vpn-filter for ALLOWManagerAccess

access-list Restrict-Manager-Access extended permit tcp any host 10.1.1.15 eq smtp
access-list Restrict-Manager-Access extended permit tcp any host 10.1.1.25 eq www
access-list Restrict-Manager-Access extended deny ip any any

Define an IP address pool for remote users;

ip local pool ssl_vpn_pool 10.9.9.1-10.9.9.100 mask 255.255.255.0

Define your group-policies. These determine if a user can login and once logged in what
access they have by tying back to the access-lists. Also a policy needs to be created that
d
enies access. The LDAP map links policies to users and the NOACCESS policy is defined in the
tunnel group as the default policy.

group-policy ALLOWSupportAccess internal
group-policy ALLOWSupportAccess attributes
banner value Welcome you are logged in with Support rights and full access.
dns-server value 10.1.2.3
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Support-Split-Tunnel
default-domain value company1.co.uk
nem enable
!
group-policy ALLOWManagerAccess internal
group-policy ALLOWManagerAccess attributes
banner value You are logged in as a Manager with limited access.
dns-server value 10.1.2.3
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
vpn-filter value Restrict-Manager-Access
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Manager-Split-Tunnel
default-domain value company1.co.uk
nem enable
hidden-shares none
file-entry disable
file-browsing disable

!
!

group-policy NOACCESS internal
group-policy NOACCESS attributes
vpn-simultaneous-logins 0
vpn-tunnel-protocol ikev1 l2tp-ipsec

Finally the tunnel-group sets the various settings for IPSEC VPN access to the Cisco ASA
and ties the other parts of the config together.

tunnel-group REMOTEVPN type remote-access
tunnel-group REMOTEVPN general-attributes
address-pool ssl_vpn_pool
authentication-server-group Company1-LDAP
authorization-server-group Company1-LDAP
authorization-server-group (inside) Company1-LDAP
default-group-policy NOACCESS
password-management password-expire-in-days 7
authorization-required


To troubleshoot any issues enable the following debugs.

debug aaa authentication enabled at level 1
debug aaa authorization enabled at level 1
debug aaa common enabled at level 15
debug ldap enabled at level 15
!
show aaa-server protocol ldap

use this command on a domain controller to find the full path of the ASAuser account:

dsquery user -samid ASAUser

Summary :

ldap attribute-map Company1-Map
map-name memberOf IETF-Radius-Class
map-value memberOf “CN=SupportStaff,OU=User Accounts,DC=1stquote,DC=co,DC=uk”
ALLOWSupportAccess
map-value memberOf “CN=Managers,OU=User Accounts,DC=1stquote,DC=co,DC=uk”
ALLOWManagerAccess
!
aaa-server Company1-LDAP protocol ldap
aaa-server Company1-LDAP (inside) host 10.1.1.2
ldap-base-dn dc=company1,dc=co,dc=uk
server-port 389
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password globalwave
ldap-login-dn CN=Administrator,CN=Users,DC=company1,DC=co,DC=uk
server-type microsoft
ldap-attribute-map Company1-Map
!

access-list Managers-Split-Tunnel standard permit host 10.1.1.15
access-list Managers-Split-Tunnel standard permit host 10.1.1.25
access-list Support-Split-Tunnel standard permit 10.0.0.0 255.0.0.0

!
ip local pool ssl_vpn_pool 10.9.9.1-10.9.9.100 mask 255.255.255.0
!
group-policy ALLOWSupportAccess internal
group-policy ALLOWSupportAccess attributes
banner value Welcome you are logged in with Support rights and full access.
dns-server value 10.1.2.3
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Support-Split-Tunnel
default-domain value company1.co.uk
nem enable
!
group-policy ALLOWManagerAccess internal
group-policy ALLOWManagerAccess attributes
banner value You are logged in as a Manager with limited access.
dns-server value 10.1.2.3
vpn-simultaneous-logins 1
vpn-idle-timeout none
vpn-tunnel-protocol ikev1 l2tp-ipsec
password-storage enable
vpn-filter value Restrict-Manager-Access
split-tunnel-policy tunnelspecified
split-tunnel-network-list value Manager-Split-Tunnel
default-domain value company1.co.uk
nem enable
hidden-shares none
file-entry disable
file-browsing disable
!
!
group-policy NOACCESS internal
group-policy NOACCESS attributes
vpn-simultaneous-logins 0
vpn-tunnel-protocol ikev1 l2tp-ipsec
!
tunnel-group REMOTEVPN type remote-access
tunnel-group REMOTEVPN general-attributes
address-pool ssl_vpn_pool
authentication-server-group Company1-LDAP
authorization-server-group Company1-LDAP
authorization-server-group (inside) Company1-LDAP
default-group-policy NOACCESS
password-management password-expire-in-days 7
authorization-required

ASA VPN LDAP Authentication + Group Membership Verification


!
!
!
!
!
!
!
!
!
!

Project Goal: The goal for this task is to authenticate VPN users via LDAP to the
Windows 2008 domain controllers. In addition to the simple AD authentication
requirement, the client wanted to match the user’s credentials against a VPN group
in the AD database, as a second layer of protection.

This second check against the AD group membership helps to ensure that the user
didn’t just obtain the VPN group password along with a user’s username and password.
In addition, it gives more control to the IT administrator to make sure that only approved
users have VPN access, not all users in the AD branch.

Requirements: In order to complete this task, the following items were needed:

1. Upgrade the ASA appliance to 8.0(4). At the time of the project, this version was
stable and allowed authentication directly to AD without the need for an additional
RADIUS services to be installed on the domain controllers.

2. A single user account with basic privileges in the AD database. For best results,
place this user in the root of the tree (Base DN).

I recommend building a test VPN group in parallel, test the authentication and then
change the production group’s authentication servers.

The first step is to create an attribute map called ASAMAP. In the map subcommands,
we match the well known Microsoft attribute
“memberOf” to a standard IETF Radius class,
which the ASA is familiar with.

The next line takes the newly created association to the path of the AD group,
in this example the group name is VPN_Users.

The final important note in this step is to notice the value being mapped to the already
existing VPN group called
ciscovpn. Now that the map name and value to be checked
has been created, it will later be associated with the VPN tunnel group.

ldap attribute-map ASAMAP
map-name memberOf IETF-Radius-Class
map-value memberOf “CN=VPN_Users,OU=Security                 Groups,OU=Groups,OU=CompanyXYZHQ,DC=companyxyz,DC=com” ciscovpn

Create the new AAA server(s) called LDAP-Auth2-AD (you can use any name you like).
In this case, these are the new 2008 servers. In addition, the communication protocol is
determined in this step. For our example, I use LDAP.

aaa-server LDAP-Auth2-AD protocol ldap

Now that we have identified the protocol as LDAP and created a new method,
we add each server independently. Just like anything else with the ASA, you must
tell it which interface to use in order to communicate with the server, in this case,
the (inside) interface. Larger clients might have their authentication servers in a DMZ.

After entering the following command, the rest of the commands are sub-commands.

aaa-server LDAP-Auth2-AD (inside) host 172.16.1.91

In this step we tell the ASA where the Base DN is for the AD tree.
This is basically the path to the root of the tree.

ldap-base-dn DC=CompanyXYZ,DC=com
ldap-scope subtree
ldap-naming-attribute sAMAccountName

As we continue with the sub commands, we provide a username and password for the
ASA to use in order to log into AD and make sure the user exists.
I usually let the Windows admin dictate the name.

In this example, the username is S_ASA_LDAP. In order to have a successful
implementation, you can use the following command to test the LDAP authentication:

“test aaa-server authentication LDAP-Auth2-AD host 172.16.1.91 username
S_ASA_LDAP password abc123“.

!

If the test fails, I recommend you stop and figure out the AD problems first.

use this command on a domain controller to find the full path of the ASAuser account:

dsquery user -samid ASAUser

Your login DN has to contain the complete location of the user ID you are using.
For example CN=ASAUser,OU=ServiceAccounts,DC=cisco,DC=com


!

ldap-login-password
ldap-login-dn CN=S_ASA_LDAP,OU=service accounts,OU=Users,
OU=CompanyXYZ HQ,DC=CompanyXYZ,DC=com
server-type Microsoft

Still in subcommands, we add our second layer of authentication by telling the ASA
to also check against the LDAP attribute created in step 1.

ldap-attribute-map ASAMAP

The next step is to point the existing production VPN tunnel group to the new
authentication servers created earlier.

First we enter the VPN group policy section, and then assign the appropriate
authentication method. Note, there are other attribute settings for this group,
however, we only care about the authentication method.

tunnel-group ciscovpn general-attributes
authentication-server-group LDAP-Auth2-AD

The ASA automatically defers to the default group policy if a user authentication
fails and no authentication method is specified, therefore, we need to make sure that
the built-in default policy is using the same authentication method.
The fiirst step is to change the default tunnel group defaultRAGroup to utilize the same
authentication method. Note: If you don’t perform these two steps, the authentication
will still work even if you remove the user from the AD group.

tunnel-group DefaultRAGroup general-attributes
authentication-server-group LDAP-Auth2-AD

Finally, the VPN default group policy attributes are basically disabled by changing
the simultaneous logins to zero.

group-policy DfltGrpPolicy attributes
vpn-simultaneous-logins 0

Now it is time to test. The ASA has a simple debug command to verify the results.

debug ldap 255

Here is a sample debug of the LDAP authentication. The only part we need for this
task is to make sure that the “memberOf” variable is being properly matched.
If the match is being performed properly, the rest depends on the users group
membership. Below we see a match with the “Users” group.

[20330] memberOf: value = CN=VPN_Users,OU=Security Groups,OU=Groups,
OU=CompanyXYZ HQ,DC=compnayxyz,DC=COM

[20330] mapped to IETF-Radius-Class: value = policy_1

In addition, the “debug ldap 255” command is very useful to see the Active Directly
Base DN path and what the server is expecting from the ASA.

In addition, this debug command can be very useful to find out where the authentication
maybe failing. For example, if the login fails, you can see if the issue was related to a
bad password, lack of communication with the server, or no group match.

Note: If you forget to disable the logins and authentication for the default VPN group,
you will see in the debug that the user is not a member of the VPN group,
yet authentication is still successful.

In conclusion, I have included a snippet from the actual running configuration:

ldap attribute-map ASAMAP
map-name memberOf IETF-Radius-Class
map-value memberOf “CN=VPN_Users,OU=Security Groups,OU=Groups,
OU=CompanyXYZ HQ,DC=CompanyXYZ,DC=com” ciscovpn
!
dynamic-access-policy-record DfltAccessPolicy
aaa-server LDAP-Auth2-AD protocol ldap
aaa-server LDAP-Auth2-AD (inside) host 172.16.1.91
ldap-base-dn DC=CompanyXYZ,DC=com
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password *
ldap-login-dn CN=S_ASA_LDAP,OU=service accounts,OU=Users,
OU=CompanyXYZ HQ,DC=CompanyXYZ,DC=com
server-type microsoft
ldap-attribute-map ASAMAP
!
aaa-server LDAP-Auth2-AD (inside) host 172.16.1.92
ldap-base-dn DC=CompanyXYZ,DC=com
ldap-scope subtree
ldap-naming-attribute sAMAccountName
ldap-login-password *
ldap-login-dn CN=S_ASA_LDAP,OU=service accounts,OU=Users,
OU=CompanyXYZ HQ,DC=CompanyXYZ,DC=com
server-type microsoft
ldap-attribute-map ASAMAP
!
tunnel-group ciscovpn general-attributes
authentication-server-group LDAP-Auth2-AD
tunnel-group DefaultRAGroup general-attributes
authentication-server-group LDAP-Auth2-AD
group-policy DfltGrpPolicy attributes
vpn-simultaneous-logins 0