I'm running Cisco ASA5520's with PIXOS 8.2(1). I have my vpn setup to authenticate users from my ldap server. I need to be able to limit them to a specific group. My login base dn is "dc=example,dc=com" Users are in dn of "uid=$username,ou=users,dc=example,dc=com"
I need to limit vpn access to people are are members in a group in a different OU. The OU I need to check is "gid=vpn,ou=groups,dc=example,dc=com"
Any ideas how I can do that?
For our ASA, even though we have AD/LDAP, we still use RADIUS. You may find this works beter. I know that doesn't answer your question though.
With that being said, have you seen this article? Looks pretty striaght forward. https://supportforums.cisco.com/docs/DOC-3843