Configure LDAP attribute maps for LDAP authorization

LDAP attribute maps are configuration elements that

  • link LDAP user or group attribute names to Cisco-recognized attribute names

  • equate attributes from AD or LDAP servers with Cisco attribute names, and

  • can map one or more LDAP attributes to one or more Cisco LDAP attributes, or to a vendor-specific attribute (VSA).

Use LDAP attribute maps for VPN access control

To assign different VPN policies or access permissions to users based on their credentials, configure LDAP authorization with LDAP attribute maps. To accomplish this configuration, configure a map that links an LDAP attribute to a group policy. The Firewall Threat Defense device assigns this policy to the user during authentication.

How LDAP attribute maps work

During a remote access VPN connection, after the AD or LDAP server returns authentication to the Firewall Threat Defense device, it uses the mapped attributes to adjust how Secure Client completes the connection.

LDAP attribute map components

  • Realm—Specifies the name of the LDAP realm. This name is used as the LDAP attribute map name.

  • Attribute Name Map—Maps the LDAP user or group attribute name to a Cisco-understandable name.

  • Attribute Value Map—Maps the value in the LDAP user or group attribute to the value of a Cisco attribute for the selected name mapping.

When a group policy is used in an LDAP attribute map, it is automatically added to the remote access VPN configuration. If you remove a group policy from the configuration, its associated LDAP attribute mapping is also removed.