You are here
SEC0147 - ASA CX Passive Authentication
Difficulty Level:
Lab Document:
<Please login to see the content>
Category:
Security
The video shows you the second method of obtaining user identity on Cisco ASA CX using Passive Authentication. We will leverage the User-to-IP mapping information provided by CDA by configuring CX device as a consumer. Once the mapping information is available to CX, minor modification will be performed on the Identity Policy and you will see how users are saved from having to enter their credentials as we saw in the Active Authentication. We will also discuss and demonstrate some caveats to this method towards the end of the lab.
Topic:
- CX Passive Authentication
- CDA Integration and Consumer Configuration
- Identities Policy
- Roaming Uers
5 comments
eceive only very few users-IP mapping on my ASA
Hi Metha,
I integrate ISE with CDA, i didn`t add domain in CDA.
I did all the steps from ASA side and CDA side, but I receive only very few users-IP mapping on my ASA.
i defined CDA as a radius in ASA configs.
I configured Ldap integration also in ASA
also i can see ASA as registered device normally under consumer devices.
any missing steps. ??
Receive only very few users-IP mapping on my ASA
Can you let us know how exactly you are configuring ASA to integrate with CDA and if there is a documentation you follow? Are you doing Identity Firewall or with Cisco CX?
ASA integration with CDA- Identity Firewalling.
Hi Metha, thanks for your kind reply,
I'm doing Identity firewalling, I can't find a recent document how to do the config on ASA side. I'm following old one (https://supportforums.cisco.com/document/80646/asa-idfw-identity-firewal...) except the section of installing the AD-agent software in AD server.
I'm only adding CDA as a radius server in ASA, and I make test from ASDM and give successful.
Thanks a lot.
ASA integration with CDA- Identity Firewalling.
We haven't seen ASA working directly with CDA so you might want to confirm with Cisco if it is supported. The most common way today is to used ASA Firepower or FTD to integrate with AD Agent or through ISE.
Do you have any video for ASA integration with CDA.
Hi Metha.
Do you have any video for ASA integration with CDA.