5-6
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 5 Identity Firewall
About the Identity Firewall
Figure 5-4 LAN -based Deployment
The following figure shows a WAN-based deployment to support a remote site. The Active Directory
server and the AD Agent are installed on the main site LAN. The clients are located at a remote site and
connect to the Identity Firewall components over a WAN.
Figure 5-5 WAN-based Deployment
The following figure also shows a WAN-based deployment to support a remote site. The Active
Directory server is installed on the main site LAN. However, the AD Agent is installed and accessed by
the clients at the remote site. The remote clients connect to the Active Directory servers at the main site
over a WAN.
Client ASA
AD Servers AD Agent
304003
LAN
NetBIOS Probe
mkg.example.com
10.1.1.2
WMI
LDAP
RADIUS
Client
ASA
AD Servers
304008
Remote Site Enterprise Main Site
NetBIOS Probe
Login/Authentication
mkg.example.com
10.1.1.2
WAN
AD Agent
WMI
RADIUS
LDAP