配置AAA server ,使用ldap协议
ciscoasa(config)#aaa-serverLDAP_SRV_GRPprotocolldap
配置AAA
ciscoasa(config-aaa-server-group)#aaa-serverLDAP_SRV_GRP(inside) host192.168.1.2 ciscoasa(config-aaa-server-host)#ldap-base-dndc=ftwsecurity,dc=cisco,dc=com ciscoasa(config-aaa-server-host)#ldap-login-dncn=admin,cn=users,dc=ftwsecurity,dc=cisco,dc=com ciscoasa(config-aaa-server-host)#ldap-login-passwordalong123 ciscoasa(config-aaa-server-host)#ldap-naming-attributesAMAccountName ciscoasa(config-aaa-server-host)#ldap-scopesubtree ciscoasa(config-aaa-server-host)#server-typemicrosoft ciscoasa(config-aaa-server-host)#exit
配置隧道组调用aaa server
ciscoasa(config)#tunnel-groupExampleGroup2general-att ciscoasa(config-tunnel-general)#authentication-server-groupLDAP_SRV_GRP 测试
可以在命令行中使用 test 命令测试您的 AAA 设置。向 AAA 服务器发送测试请求,并在命令行中显示结果。
ciscoasa#testaaa-serverauthenticationLDAP_SRV_GRPhost192.168.1.2 usernamekatepasswordalong123 INFO:AttemptingAuthenticationtesttoIPaddress<192.168.1.2> (timeout:12seconds) INFO:AuthenticationSuccessful