31-23
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
Chapter 31 Configuring AAA Servers and the Local Database
Adding an Authentication Prompt
To map the LDAP attribute names used in your organization to their Cisco counterparts on the adaptive
security appliance, perform the following steps:
Step 1 Choose Configuration > Remote Access VPN > AAA Local Users > LDAP Attribute Map, and then
click Add.
The Add LDAP Attribute Map dialog box appears with the Map Name tab active.
Step 2 In the Name field, add a name for the map.
Step 3 In the Customer Name field, add the name of your organization’s corresponding attribute.
Step 4 From the Cisco Name drop-down list, choose an attribute.
Step 5 Click Add.
Step 6 To add more names, repeat Steps 1 through 5.
Step 7 To map the customer names, click the Map Value tab.
Step 8 Click Add.
The Add LDAP Attributes Map Value dialog box appears.
Step 9 Choose the attribute from the Customer Name drop-down list.
Step 10 In the Customer Value field, add the value for this attribute.
Step 11 In the Cisco Value field, add the Cisco value to which the value in Step 10 maps.
Step 12 Click Add.
The values are mapped.
Step 13 To map more names, repeat Steps 8 through 12.
Step 14 Click OK to return to the Map Value tab, and then click OK again to close the dialog box.
Step 15 In the LDAP Attribute Map pane, click Apply.
The value mappings are saved to the running configuration.
Adding an Authentication Prompt
You can specify text to display to the user during the AAA authentication challenge process. You can
specify the AAA challenge text for HTTP, FTP, and Telnet access through the adaptive security appliance
when requiring user authentication from TACACS+ or RADIUS servers. This text is primarily for
cosmetic purposes and appears above the username and password prompts that users see when they log
in.
If you do not specify an authentication prompt, users see the following when authenticating with a
RADIUS or TACACS+ server:
Connection Type Default Prompt
FTP FTP authentication
HTTP HTTP Authentication
Telnet None