

If your network is live, make sure that you understand the potential impact of any command. All of the devices used in this document started with a cleared (default) configuration. The information in this document was created from the devices in a specific lab environment. The information in this document is based on these software and hardware versions:Ĭisco 5500 Series Adaptive Security Appliance (ASA) that runs the software version 8.0(x) and laterĬisco Adaptive Security Device Manager (ASDM) version 6.x for ASA 8.xĬisco An圜onnect VPN Client 2.2 with MAC Support Familiarity with AD group membership, user properties as well as LDAP objects help in the correlation of the authorization process between certificate attributes and AD/LDAP objects. Prerequisites RequirementsĪ basic understanding of Cisco ASA, Cisco An圜onnect Client, Microsoft AD/LDAP and Public Key Infrastructure (PKI) is beneficial in the comprehension of the complete setup. This document also covers advanced features such as OCSP, LDAP attribute maps and Dynamic Access Polices (DAP).

The configuration in this guide uses Microsoft AD/LDAP server. The scope of this document is to cover the configuration of Cisco ASA with Adaptive Security Device Manager (ASDM), Cisco An圜onnect VPN Client and Microsoft Active Directory (AD)/Lightweight Directory Access Protocol (LDAP). This document provides a sample configuration on Cisco Adaptive Security Appliance (ASA) for An圜onnect VPN remote access for MAC Support with the Common Access Card (CAC) for authentication.
