cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1942
Views
0
Helpful
1
Replies

Cisco ASA Group Policies and Duo

Not applicable

Hello,

I’ve implemented Duo with my Cisco ASA using SAML but am I correct in assuming that I can’t assign different group policies using the ASA? Would I be better off using a RADIUS server with Duo?

Thanks for the help,

Derrick

1 Reply 1

DuoKristina
Cisco Employee
Cisco Employee

Our RADIUS implementation is unable to send LDAP group information directly from an LDAP primary authentication source. You do have a few options here though:

1: ASA > [Duo RADIUS Proxy(Duo Authentication Proxy Reference | Duo Security) as primary] > NPS or other upstream RADIUS primary auth source that can send group info in a RADIUS attribute.

With this config you’d want to make sure to set the pass_through_all option for both the RADIUS server and client configurations in the Duo proxy’s authproxy.cfg file.

2: ASA > LDAP primary auth PLUS ASA > Duo RADIUS proxy only for secondary auth. The group info for assigning policies comes directly from your LDAP directory.

Duo, not DUO.
Quick Links