Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > ASA5500 OpenLDAP AAA Server

Reply
Thread Tools

ASA5500 OpenLDAP AAA Server

 
 
nobody@comcast.net
Guest
Posts: n/a
 
      06-29-2006
Has anyone had success having an ASA 5500 use an openLDAP server as an
aaa-server? I've read what I could, all of it relating to
ActiveDirectory and have tried several configurations with no success.
It seems suggested that I would work, when I run openLDAP in debug
mode I see the connections and name lookups but the ASA always fails.

The openLDAP server is currently servicing other applications just
fine, apache, pam, and a couple of others. The problem must be with
the ASA.

What am I missing?

Thanks

 
Reply With Quote
 
 
 
 
Chad Mahoney
Guest
Posts: n/a
 
      06-29-2006

wrote:
> Has anyone had success having an ASA 5500 use an openLDAP server as an
> aaa-server? I've read what I could, all of it relating to
> ActiveDirectory and have tried several configurations with no success.
> It seems suggested that I would work, when I run openLDAP in debug
> mode I see the connections and name lookups but the ASA always fails.
>
> The openLDAP server is currently servicing other applications just
> fine, apache, pam, and a couple of others. The problem must be with
> the ASA.
>
> What am I missing?
>
> Thanks


What version of code are you running. I first *tried* to configure LDAP
with code 7.11 and it just would not work, opened a TAC case and was
told to jump to atleast 7.12 once I did that the LDAP config to an
active directory server went with no problems.

Thanks...

Chad

 
Reply With Quote
 
 
 
 
nobody@comcast.net
Guest
Posts: n/a
 
      07-01-2006
On 29 Jun 2006 14:11:29 -0700, "Chad Mahoney" <>
wrote:

>
> wrote:
>> Has anyone had success having an ASA 5500 use an openLDAP server as an
>> aaa-server? I've read what I could, all of it relating to
>> ActiveDirectory and have tried several configurations with no success.
>> It seems suggested that I would work, when I run openLDAP in debug
>> mode I see the connections and name lookups but the ASA always fails.
>>
>> The openLDAP server is currently servicing other applications just
>> fine, apache, pam, and a couple of others. The problem must be with
>> the ASA.
>>
>> What am I missing?
>>
>> Thanks

>
>What version of code are you running. I first *tried* to configure LDAP
>with code 7.11 and it just would not work, opened a TAC case and was
>told to jump to atleast 7.12 once I did that the LDAP config to an
>active directory server went with no problems.
>
>Thanks...
>
>Chad


Thanks for the reply.

My show ver begins as follows, I'm guessing I'm already on 7.12?

Cisco Adaptive Security Appliance Software Version 7.1(2)
Device Manager Version 5.1(2)

Compiled on Tue 14-Mar-06 17:00 by dalecki
System image file is "disk0:/asa712-k8.bin"
Config file at boot was "startup-config"

radasa up 2 days 7 hours

Hardware: ASA5510, 256 MB RAM, CPU Pentium 4 Celeron 1600 MHz
Internal ATA Compact Flash, 64MB
BIOS Flash M50FW080 @ 0xffe00000, 1024KB


When I test using the java interface, and debug ldap and aaa, debug
says authentication passed it then gets user attributes and the gui
says test failed. No additional debug information is provided, like
what ldap attribute it didn't find or like.

I can't find anything that would describe required ldap fields or at
least required ldap attribute maps.

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
aaa<br /> gets turned into aaa<BR> with innerHTML yawnmoth Javascript 4 04-22-2009 01:09 AM
aaa authorization and aaa accounting with Cisco ACS and 1231 AP's Chris_D Cisco 4 08-01-2005 08:03 AM
the different between aaa m1[100] and aaa *p = new [100] C++ 5 03-15-2005 08:22 AM
Help needed:: Openldap issue - - LDAP_OPERATIONS_ERROR Server encountered Durairaj Avasi Perl 1 04-06-2004 11:17 PM
Help needed:: Openldap issue - - LDAP_OPERATIONS_ERROR Server encountered Durairaj Avasi Perl Misc 1 04-06-2004 06:46 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57