View Cart
0 Items | Total: US$0.00
Welcome,      Register

You are here

SEC0147 - ASA CX Passive Authentication

Average: 5 (1 vote)
Difficulty Level: 
Lab Document: 
<Please login to see the content>
The video shows you the second method of obtaining user identity on Cisco ASA CX using Passive Authentication. We will leverage the User-to-IP mapping information provided by CDA by configuring CX device as a consumer. Once the mapping information is available to CX, minor modification will be performed on the Identity Policy and you will see how users are saved from having to enter their credentials as we saw in the Active Authentication. We will also discuss and demonstrate some caveats to this method towards the end of the lab.
  • CX Passive Authentication
  • CDA Integration and Consumer Configuration
  • Identities Policy
  • Roaming Uers

About Author

Metha Cheiwanichakorn, CCIE#23585 (RS, Sec, SP), is a Cisco networking enthusiast with years of experience in the industry. He is currently working as a consulting engineer for a Cisco partner. As a founder of and an instructor at, Metha enjoys learning and challenges himself with new Cisco technologies.


Hi Metha,
I integrate ISE with CDA, i didn`t add domain in CDA.
I did all the steps from ASA side and CDA side, but I receive only very few users-IP mapping on my ASA.
i defined CDA as a radius in ASA configs.
I configured Ldap integration also in ASA
also i can see ASA as registered device normally under consumer devices.

any missing steps. ??

Can you let us know how exactly you are configuring ASA to integrate with CDA and if there is a documentation you follow? Are you doing Identity Firewall or with Cisco CX?

Hi Metha, thanks for your kind reply,
I'm doing Identity firewalling, I can't find a recent document how to do the config on ASA side. I'm following old one ( except the section of installing the AD-agent software in AD server.
I'm only adding CDA as a radius server in ASA, and I make test from ASDM and give successful.

Thanks a lot.

We haven't seen ASA working directly with CDA so you might want to confirm with Cisco if it is supported.  The most common way today is to used ASA Firepower or FTD to integrate with AD Agent or through ISE.

Hi Metha.
Do you have any video for ASA integration with CDA.

Lab Minutes Classifieds