<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ASA LDAP Auth the nice and easy way.</title>
	<atom:link href="http://www.staticnat.com/WP/2007/08/10/asa-ldap-auth-the-nice-and-easy-way/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.staticnat.com/WP/2007/08/10/asa-ldap-auth-the-nice-and-easy-way/</link>
	<description>static (INSIDE,OUTSIDE) 127.0.01 127.0.0.1 netmask 255.255.255.255</description>
	<lastBuildDate>Thu, 17 Nov 2011 23:44:31 -0500</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: StaticNAT &#187; Blog Archive &#187; Get Your ACS in Order!</title>
		<link>http://www.staticnat.com/WP/2007/08/10/asa-ldap-auth-the-nice-and-easy-way/comment-page-1/#comment-26497</link>
		<dc:creator>StaticNAT &#187; Blog Archive &#187; Get Your ACS in Order!</dc:creator>
		<pubDate>Sun, 12 Dec 2010 07:25:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.staticnat.com/WP/2007/08/10/asa-ldap-auth-the-nice-and-easy-way/#comment-26497</guid>
		<description>[...] ASA LDAP Auth the nice and easy way.     This entry was posted on Tuesday, October 26th, 2010 at 10:43 pm and is filed under Cisco, Hardware, On the Job. You can follow any responses to this entry through the RSS 2.0 feed.You can leave a response, or trackback from your own site.         blog comments powered by Disqus  /* [...]</description>
		<content:encoded><![CDATA[<p>[...] ASA LDAP Auth the nice and easy way.     This entry was posted on Tuesday, October 26th, 2010 at 10:43 pm and is filed under Cisco, Hardware, On the Job. You can follow any responses to this entry through the RSS 2.0 feed.You can leave a response, or trackback from your own site.         blog comments powered by Disqus  /* [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gmsmith</title>
		<link>http://www.staticnat.com/WP/2007/08/10/asa-ldap-auth-the-nice-and-easy-way/comment-page-1/#comment-18450</link>
		<dc:creator>gmsmith</dc:creator>
		<pubDate>Wed, 31 Dec 2008 01:57:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.staticnat.com/WP/2007/08/10/asa-ldap-auth-the-nice-and-easy-way/#comment-18450</guid>
		<description>So, as I mentioned in email, I got the 1 in 5 at Cisco TAC. In my last real job, we had a chart of companies and their tech support. Something like:

Cisco - 1 in 5 actually knew something
Sun - 1 in 10 actually knew something
Salesforce - 1 in 100 actually knew something
RedHat - Yeah, good luck 

Anyway, for the details....I have tested this on my home setup and it works great...

Essentially if you follow the direction on the link above and then issue the following at a config t prompt:

Group-policy noconnection internal

group-policy noconnection attributes

 vpn-simultaneous-logins 0

exit

tunnel-group &lt;&gt; general-attributes

no default-group-policy &lt;&gt;

default-group-policy noconnection

*The lines above will switch the default group policy on the &lt;&gt; group to be noconnection which prevents access to the ASA for users that do not have a gidNumber equals to the gidNumber you set.</description>
		<content:encoded><![CDATA[<p>So, as I mentioned in email, I got the 1 in 5 at Cisco TAC. In my last real job, we had a chart of companies and their tech support. Something like:</p>
<p>Cisco &#8211; 1 in 5 actually knew something<br />
Sun &#8211; 1 in 10 actually knew something<br />
Salesforce &#8211; 1 in 100 actually knew something<br />
RedHat &#8211; Yeah, good luck </p>
<p>Anyway, for the details&#8230;.I have tested this on my home setup and it works great&#8230;</p>
<p>Essentially if you follow the direction on the link above and then issue the following at a config t prompt:</p>
<p>Group-policy noconnection internal</p>
<p>group-policy noconnection attributes</p>
<p> vpn-simultaneous-logins 0</p>
<p>exit</p>
<p>tunnel-group &lt;&gt; general-attributes</p>
<p>no default-group-policy &lt;&gt;</p>
<p>default-group-policy noconnection</p>
<p>*The lines above will switch the default group policy on the &lt;&gt; group to be noconnection which prevents access to the ASA for users that do not have a gidNumber equals to the gidNumber you set.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cratejockey</title>
		<link>http://www.staticnat.com/WP/2007/08/10/asa-ldap-auth-the-nice-and-easy-way/comment-page-1/#comment-18425</link>
		<dc:creator>cratejockey</dc:creator>
		<pubDate>Mon, 29 Dec 2008 18:31:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.staticnat.com/WP/2007/08/10/asa-ldap-auth-the-nice-and-easy-way/#comment-18425</guid>
		<description>Thanks Greg!  He provided the following link as a follow up to our off-line conversation.

http://209.85.135.104/translate_c?hl=en&amp;sl=fr&amp;tl=en&amp;u=http://pm.itguys.fr/blog/tags/asa/&amp;usg=ALkJrhj0dOIxqsafNO8RSkeKrUNxzasSeQ

Plus he has an open TAC case and has offered to share his results.</description>
		<content:encoded><![CDATA[<p>Thanks Greg!  He provided the following link as a follow up to our off-line conversation.</p>
<p><a href="http://209.85.135.104/translate_c?hl=en&#038;sl=fr&#038;tl=en&#038;u=http://pm.itguys.fr/blog/tags/asa/&#038;usg=ALkJrhj0dOIxqsafNO8RSkeKrUNxzasSeQ" rel="nofollow">http://209.85.135.104/translate_c?hl=en&#038;sl=fr&#038;tl=en&#038;u=http://pm.itguys.fr/blog/tags/asa/&#038;usg=ALkJrhj0dOIxqsafNO8RSkeKrUNxzasSeQ</a></p>
<p>Plus he has an open TAC case and has offered to share his results.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gmsmith</title>
		<link>http://www.staticnat.com/WP/2007/08/10/asa-ldap-auth-the-nice-and-easy-way/comment-page-1/#comment-17627</link>
		<dc:creator>gmsmith</dc:creator>
		<pubDate>Sun, 07 Dec 2008 01:14:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.staticnat.com/WP/2007/08/10/asa-ldap-auth-the-nice-and-easy-way/#comment-17627</guid>
		<description>Quick question for you, I am trying to limit my LDAP authentication to a specific group in OS X OpenDirectory (10.5.5), but I can&#039;t seem to do it...did you have any luck with this?</description>
		<content:encoded><![CDATA[<p>Quick question for you, I am trying to limit my LDAP authentication to a specific group in OS X OpenDirectory (10.5.5), but I can&#8217;t seem to do it&#8230;did you have any luck with this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jfh6200</title>
		<link>http://www.staticnat.com/WP/2007/08/10/asa-ldap-auth-the-nice-and-easy-way/comment-page-1/#comment-5149</link>
		<dc:creator>jfh6200</dc:creator>
		<pubDate>Fri, 23 Nov 2007 15:20:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.staticnat.com/WP/2007/08/10/asa-ldap-auth-the-nice-and-easy-way/#comment-5149</guid>
		<description>Josh, this is an excelletn post...You can find a sample config @ my website (http://6200networks.com/?p=25)...Keep up the great work man.

-Joe</description>
		<content:encoded><![CDATA[<p>Josh, this is an excelletn post&#8230;You can find a sample config @ my website (<a href="http://6200networks.com/?p=25" rel="nofollow">http://6200networks.com/?p=25</a>)&#8230;Keep up the great work man.</p>
<p>-Joe</p>
]]></content:encoded>
	</item>
</channel>
</rss>

